Suspicious CMD Shell Output Redirect

Rule Info

Name
Suspicious CMD Shell Output Redirect
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
Date
2024-04-29 00:00:00
Modified
None
Id
63fa672f-6ca3-40ee-a45d-2dbdc514a539
Tags
attack.defense_evasion attack.t1218
Type
Nextron Sigma feed only (private)

Rule History