Potential User Profile Reconnaissance via CommandLine

Rule Info

Name
Potential User Profile Reconnaissance via CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential user profile reconnaissance activity by identifying command-line executions of 'cmd.exe' and 'reg.exe' that query user directories and registry keys associated with user profiles.
Date
2026-04-03 00:00:00
Modified
None
Id
a65cfb85-180a-4343-9be8-5fc6f0afd7ff
Tags
attack.discovery attack.t1087.001
Type
Nextron Sigma feed only (private)

Rule History