Suspicious PowerShell Use of DIR Alias with Glob Pattern

Rule Info

Name
Suspicious PowerShell Use of DIR Alias with Glob Pattern
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell process creation using the DIR alias with a glob pattern, which may indicate suspicious and obfuscated activity.
Date
2026-03-20 00:00:00
Modified
None
Id
7e5edc86-7855-41df-ab21-938ddc97147e
Tags
attack.execution attack.defense-evasion attack.t1059.001 attack.t1027.010
Type
Nextron Sigma feed only (private)

Rule History