Suspicious PowerShell System Reconnaissance Via DotNET Environment Class

Rule Info

Name
Suspicious PowerShell System Reconnaissance Via DotNET Environment Class
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell commands that access .NET [Environment] class properties for system reconnaissance when spawned from a suspicious location. Attackers use these properties to enumerate user and session context, system hardware info, OS version, filesystem paths and/or environment variables during post-exploitation profiling prior to payload staging or lateral movement. Rather than relying on external tools or registry queries, attackers may gather system information directly from the .NET Environment class while executing from user-writable directories such as Temp, Downloads, or Public folders.
Date
2026-09-14 00:00:00
Modified
None
Id
5b90b444-ddcf-467c-9f39-adda7fdd9031
Tags
attack.discovery attack.t1082 attack.t1033 attack.t1083
Type
Nextron Sigma feed only (private)

Rule History