Rule Info
Name
File Operation via .NET Class
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of dotnet method in command lines which could be used for unauthorized file operations such as copying files.
It could indicate suspicious activity because there are many normal ways to copy files in Windows, thus adversary may use this rarely used method to avoid detection.
Reference
Internal Research
Date
2026-02-06 00:00:00
Modified
None
Id
6b9e0d40-8b3a-41e4-a3a3-5872a9232cd9
Tags
attack.defense-evasion
Type
Nextron Sigma feed only (private)
