Rule Info
Name
Process Termination via PowerShell Enumeration Pipeline
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Tim Rauch (Nextron Systems)
Description
Detects PowerShell commands that enumerate all running processes and terminate them
via a pipeline or loop. It is commonly observed in post-exploitation tooling and ransomware
precursor activity where specific process categories such as security tools, backup agents,
or database services are killed before payload execution.
Date
2026-09-30 00:00:00
Modified
None
Id
70a1f932-d50b-4dc2-a699-d8724085937e
Tags
attack.defense-impairment attack.t1685 attack.impact attack.t1489
Type
Nextron Sigma feed only (private)
