Rule Info
Name
Suspicious Service Installation with Potentially Malicious CommandLine - Security
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects installation of suspicious services with command line patterns commonly associated with malicious activity, such as the use of cmd.exe with pipe commands or PowerShell with encoded commands, which may indicate attempts to establish persistence or execute malicious payloads.
Date
2026-03-03 00:00:00
Modified
None
Id
9c6b1d2e-4f8a-5b3c-0d7e-2a9f6c5b8d4e
Tags
attack.persistence attack.privilege-escalation attack.t1543.003
Type
Nextron Sigma feed only (private)
