Potential Enumeration and Terminaation of User Sessions

Rule Info

Name
Potential Enumeration and Terminaation of User Sessions
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell script blocks containing both quser and logoff commands, which might indicate malware attempting to enumerate and forcefully terminate user sessions on a compromised host
Date
2025-03-14 00:00:00
Modified
None
Id
362d6351-ed4e-4c3e-8c2d-c70fb9e087a4
Tags
attack.execution attack.t1059.001
Type
Nextron Sigma feed only (private)

Rule History