Rule Info
Name
Suspicious PowerShell System Reconnaissance Via DotNET Environment Class
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell commands that access .NET [Environment] class properties for
system reconnaissance when spawned from a suspicious location. Attackers use these
properties to enumerate user and session context, system hardware info, OS version,
filesystem paths and/or environment variables during post-exploitation profiling prior
to payload staging or lateral movement. Rather than relying on external tools or registry
queries, attackers may gather system information directly from the .NET Environment class
while executing from user-writable directories such as Temp, Downloads, or Public folders.
Reference
Date
2026-09-14 00:00:00
Modified
None
Id
5b90b444-ddcf-467c-9f39-adda7fdd9031
Tags
attack.discovery attack.t1082 attack.t1033 attack.t1083
Type
Nextron Sigma feed only (private)
