
Rule Info
Name
Process Execution from PerfLogs Directory
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects process execution from the Windows PerfLogs directory, which is unusual and potentially suspicious.
PerfLogs is a folder used by Windows for log collection and highly unlikely place for processes to execute from.
Reference
Internal Research
Date
2025-03-24 00:00:00
Modified
None
Id
55b68201-16e9-4e01-a9dd-bedf1799a315
Tags
attack.execution attack.t1204.002
Type
Nextron Sigma feed only (private)