Notepad Password Files Discovery

Rule Info

Name
Notepad Password Files Discovery
Author
The DFIR Report
Description
Detects the execution of Notepad to open a file that has the string "password" which may indicate unauthorized access to credentials or suspicious activity.
Date
2025-02-21 00:00:00
Modified
None
Id
3b4e950b-a3ea-44d3-877e-432071990709
Tags
attack.discovery attack.t1083
Type
Community Rule

Rule History

Author
Title
Date
Commit
DFIR-Detection
Merge PR #5198 from @DFIR-Detection - Add `Notepad Password Files Discovery`
2025-03-04