PowerShell One-Liner Credential Pattern Search

Rule Info

Name
PowerShell One-Liner Credential Pattern Search
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell or pwsh one-liners whose command line combines a regex or string-matching primitive with common credential-related keywords. It might indicate an attempt of credential harvesting across local files, including config files, source code, chat history, etc. looking for secrets such as API keys, tokens, passwords, or SSH keys.
Date
2026-06-11 00:00:00
Modified
None
Id
837493bb-8c67-49f2-99ba-1deb97db22da
Tags
attack.credential-access attack.t1552.001
Type
Nextron Sigma feed only (private)

Rule History