Join our Newsletter — 33% off our NHI Course
Foundations & NHI Taxonomy

Search-MS

← Back to Glossary
By NHI Mgmt Group Updated September 23, 2026 Domain: Foundations & NHI Taxonomy

Search-ms is a Windows search URI and file-related mechanism that can launch a saved search in Explorer. Attackers abuse it to trigger hidden remote queries, redirect users into malicious shares, and disguise the real source of a file. The technique is especially useful for obscuring WebDAV or tunnel-based delivery.

How Search-ms Works

Search-ms is a Windows search URI that opens a saved search in File Explorer. On its own, it is a convenience mechanism for finding files and folders, but it becomes security-relevant because the URI can also point users toward remote content or deceptive search locations.

The mechanism matters because the path a user sees is not always the path that actually delivers the file. Attackers can make a remote location look like a normal search result, which helps blur the boundary between local file discovery and network retrieval. That is why search-ms is often discussed alongside WebDAV, SMB, and other remote file delivery paths.

In practice, the term covers both the URI scheme and the abuse pattern. The benign use case is a saved search; the malicious use case is using the same handler to steer execution and attention toward content that appears local, but is sourced elsewhere.

Why Attackers Abuse It

Attackers like search-ms because it helps hide infrastructure and weaken user scrutiny. A crafted search can redirect a victim into a share, tunnel, or remote file source without making the delivery path obvious at first glance.

This is useful when the attacker wants to disguise the origin of a payload, especially when the final file is fetched over a path that would otherwise look suspicious. The technique is less about breaking the browser or file explorer and more about exploiting user trust in the Windows shell and in search-like interfaces.

The abuse pattern also helps separate the visible artifact from the real delivery mechanism. The user may remember opening a search result, not a network location, which makes incident review and user reporting less reliable.

Security Implications

Search-ms is a small feature with outsized implications because it can assist initial access, payload delivery, and source obfuscation. It is especially relevant when the attacker combines it with malicious documents, shortcut files, archive content, or a remote share that hosts the actual payload.

The main security concern is not the URI alone, but the way it can normalize remote retrieval inside an interface users associate with local content. That weakens the user’s ability to distinguish benign search behavior from a delivery chain designed to reach untrusted infrastructure.

For defenders, the important signal is the relationship between the URI, the Explorer action, and the network destination. The risk increases when the resulting path crosses trust boundaries, reaches a file share under attacker control, or is used to conceal the true origin of an executable or document.

Detection and Defensive Context

Search-ms is best handled as part of shell, endpoint, and network monitoring rather than as a standalone indicator. Useful visibility comes from correlating Explorer activity, URI invocation, and outbound access to remote shares or WebDAV endpoints.

Defensive review should focus on whether the search target is local or remote, whether the path is expected, and whether the user action matches the surrounding process chain. When the search opens content from an unusual location, the downstream file origin and follow-on execution path matter more than the search window itself.

For broader context on the threat pattern around hidden delivery and file-source disguise, see The 52 NHI breaches Report for real-world compromise patterns, and FIRST EPSS for prioritising exploitation-likely exposure when related weaknesses surface in the environment.

Risk and Threat Considerations

Search-ms can be abused to obscure the source of a file, redirect victims into malicious shares, and make remote retrieval look like ordinary search behavior. That creates a practical risk of phishing, malware delivery, and investigation blind spots when users or defenders trust the visible Explorer path too much.

Failure mechanism: The URI handler allows a crafted search experience to bridge local-looking file interaction into remote content access, which attackers can pair with WebDAV, tunnel-based hosting, or hostile shares.

Impact: Victims may open or execute content from an untrusted source while believing it came from a local search result, and defenders may misread the provenance of the file during triage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1210 — Exploitation of Remote ServicesSearch-ms abuse often pivots victims into remote shares or WebDAV paths.
T1204 — User ExecutionThe technique relies on a victim opening a crafted search or file path.
T1021 — Remote ServicesMalicious search targets can disguise access to remote file delivery infrastructure.
Recommendation — Hunt for remote-service abuse when Explorer activity reaches untrusted network shares. Correlate user-initiated Explorer actions with the resulting network fetch and file execution. Monitor remote-service traffic that follows search-driven shell interactions.
CIS Controls v88 — Audit Log ManagementExplorer and network logs help reconstruct search-ms driven delivery chains.
10 — Malware DefensesSearch-ms is used in file-delivery chains that can culminate in malware execution.
Recommendation — Collect endpoint and network logs that preserve URI launches and remote file retrieval. Inspect files delivered through search-driven paths before execution.

Practitioner Guidance

What to watch for: Treat unexpected search-ms launches, especially those followed by remote file access, as a signal to inspect the parent process, destination path, and downloaded artifact chain. The key judgement is provenance, not just whether Explorer opened successfully.

Practitioner takeaway: If the visible interface suggests local search but the path resolves to a remote share or tunnel, investigate it like a delivery mechanism, not a benign search event.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org