Suspicious Where.exe Execution With Glob Patterns

Rule Info

Name
Suspicious Where.exe Execution With Glob Patterns
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the execution of where.exe with glob patterns (wildcards) that may indicate command line obfuscation attempts to search for or identify system utilities.
Date
2026-03-04 00:00:00
Modified
None
Id
8e3c5a7f-1b2d-4e6a-9c8f-0d1e2f3a4b5c
Tags
attack.defense-evasion attack.t1027.010 attack.discovery attack.t1518
Type
Nextron Sigma feed only (private)

Rule History