
Rule Info
Name
Suspicious Image Load From PerfLogs Directory
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious image loads from PerfLogs directory which may indicate malicious activity
Reference
Internal Research
Date
2025-03-24 00:00:00
Modified
None
Id
43615bc7-4227-4674-8a88-b659917526ba
Tags
attack.execution attack.t1204.002
Type
Nextron Sigma feed only (private)