Search-ms is a Windows search URI and file-related mechanism that can launch a saved search in Explorer. Attackers abuse it to trigger hidden remote queries, redirect users into malicious shares, and disguise the real source of a file. The technique is especially useful for obscuring WebDAV or tunnel-based delivery.
How Search-ms Works
Search-ms is a Windows search URI that opens a saved search in File Explorer. On its own, it is a convenience mechanism for finding files and folders, but it becomes security-relevant because the URI can also point users toward remote content or deceptive search locations.
The mechanism matters because the path a user sees is not always the path that actually delivers the file. Attackers can make a remote location look like a normal search result, which helps blur the boundary between local file discovery and network retrieval. That is why search-ms is often discussed alongside WebDAV, SMB, and other remote file delivery paths.
In practice, the term covers both the URI scheme and the abuse pattern. The benign use case is a saved search; the malicious use case is using the same handler to steer execution and attention toward content that appears local, but is sourced elsewhere.
Why Attackers Abuse It
Attackers like search-ms because it helps hide infrastructure and weaken user scrutiny. A crafted search can redirect a victim into a share, tunnel, or remote file source without making the delivery path obvious at first glance.
This is useful when the attacker wants to disguise the origin of a payload, especially when the final file is fetched over a path that would otherwise look suspicious. The technique is less about breaking the browser or file explorer and more about exploiting user trust in the Windows shell and in search-like interfaces.
The abuse pattern also helps separate the visible artifact from the real delivery mechanism. The user may remember opening a search result, not a network location, which makes incident review and user reporting less reliable.
Security Implications
Search-ms is a small feature with outsized implications because it can assist initial access, payload delivery, and source obfuscation. It is especially relevant when the attacker combines it with malicious documents, shortcut files, archive content, or a remote share that hosts the actual payload.
The main security concern is not the URI alone, but the way it can normalize remote retrieval inside an interface users associate with local content. That weakens the user’s ability to distinguish benign search behavior from a delivery chain designed to reach untrusted infrastructure.
For defenders, the important signal is the relationship between the URI, the Explorer action, and the network destination. The risk increases when the resulting path crosses trust boundaries, reaches a file share under attacker control, or is used to conceal the true origin of an executable or document.
Detection and Defensive Context
Search-ms is best handled as part of shell, endpoint, and network monitoring rather than as a standalone indicator. Useful visibility comes from correlating Explorer activity, URI invocation, and outbound access to remote shares or WebDAV endpoints.
Defensive review should focus on whether the search target is local or remote, whether the path is expected, and whether the user action matches the surrounding process chain. When the search opens content from an unusual location, the downstream file origin and follow-on execution path matter more than the search window itself.
For broader context on the threat pattern around hidden delivery and file-source disguise, see The 52 NHI breaches Report for real-world compromise patterns, and FIRST EPSS for prioritising exploitation-likely exposure when related weaknesses surface in the environment.
Risk and Threat Considerations
Search-ms can be abused to obscure the source of a file, redirect victims into malicious shares, and make remote retrieval look like ordinary search behavior. That creates a practical risk of phishing, malware delivery, and investigation blind spots when users or defenders trust the visible Explorer path too much.
Failure mechanism: The URI handler allows a crafted search experience to bridge local-looking file interaction into remote content access, which attackers can pair with WebDAV, tunnel-based hosting, or hostile shares.
Impact: Victims may open or execute content from an untrusted source while believing it came from a local search result, and defenders may misread the provenance of the file during triage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1210 — Exploitation of Remote Services | Search-ms abuse often pivots victims into remote shares or WebDAV paths. |
| T1204 — User Execution | The technique relies on a victim opening a crafted search or file path. | |
| T1021 — Remote Services | Malicious search targets can disguise access to remote file delivery infrastructure. | |
| Recommendation — Hunt for remote-service abuse when Explorer activity reaches untrusted network shares. Correlate user-initiated Explorer actions with the resulting network fetch and file execution. Monitor remote-service traffic that follows search-driven shell interactions. | ||
| CIS Controls v8 | 8 — Audit Log Management | Explorer and network logs help reconstruct search-ms driven delivery chains. |
| 10 — Malware Defenses | Search-ms is used in file-delivery chains that can culminate in malware execution. | |
| Recommendation — Collect endpoint and network logs that preserve URI launches and remote file retrieval. Inspect files delivered through search-driven paths before execution. | ||
Practitioner Guidance
What to watch for: Treat unexpected search-ms launches, especially those followed by remote file access, as a signal to inspect the parent process, destination path, and downloaded artifact chain. The key judgement is provenance, not just whether Explorer opened successfully.
Practitioner takeaway: If the visible interface suggests local search but the path resolves to a remote share or tunnel, investigate it like a delivery mechanism, not a benign search event.
Related resources from NHI Mgmt Group
- Why do search-ms files, LNK launchers, and WebDAV-hosted payloads increase compromise risk in targeted phishing?
- How can organisations decide whether video search is ready for production use?
- How should organisations respond when search ads lead to AI platform malware delivery?
- Who is accountable when an agentic IDE turns search into execution?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org