Possible Smbexec Execution Pattern

Rule Info

Name
Possible Smbexec Execution Pattern
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects reading and deleting the temporary output file (__output) via UNC path. This is a possible pattern of Smbexec execution where the output file is read and deleted after the command execution.
Date
2025-02-06 00:00:00
Modified
None
Id
a4186845-db18-43d5-8427-a887890e9a19
Tags
attack.lateral-movement attack.persistence attack.t1021.002
Type
Nextron Sigma feed only (private)

Rule History