Rule Info
Name
Senstitive File Access via Cmd Utility
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the usage of windows inbuilt cmd.exe utility to access sensitive files such as configuration files,
certificate files, and password files. It might indicate an adversary attempting to access sensitive files
for credential access or collection purposes via reverse shell or cli interaction.
Date
2026-08-26 00:00:00
Modified
None
Id
a3f7c2d1-8b4e-4f9a-b2e5-6c1d0a7e3f8b
Tags
attack.credential-access attack.t1552.001 attack.t1552.004 attack.collection attack.t1005
Type
Nextron Sigma feed only (private)
