Potential IIS Reconnaissance via AppCmd.Exe Utility

Rule Info

Name
Potential IIS Reconnaissance via AppCmd.Exe Utility
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential reconnaissance activity targeting Internet Information Services (IIS) web servers through the use of the AppCmd.exe utility. AppCmd.exe is a command-line tool used for managing IIS configurations and can be leveraged by attackers to gather information about the server environment, including sites, application pools, and modules.
Date
2026-04-03 00:00:00
Modified
None
Id
2419cb99-df6b-4735-9ee6-86c5ea24b899
Tags
attack.discovery attack.t1087 attack.t1046
Type
Nextron Sigma feed only (private)

Rule History