
Rule Info
Name
Possible Atexec Execution Pattern - Remote Share Access
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the access to ADMIN$ for the .tmp file to be deleted.
This is a possible pattern of Atexec execution where the .tmp file is deleted after the command execution.
Reference
Date
2025-02-07 00:00:00
Modified
None
Id
631e10b1-493b-42fb-ba2e-d73e7e467c0c
Tags
attack.lateral-movement attack.persistence attack.t1021.002
Type
Nextron Sigma feed only (private)