Rule Info
Name
Potential User Profile Reconnaissance via CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential user profile reconnaissance activity by identifying command-line executions of 'cmd.exe' and 'reg.exe' that query user directories and registry keys associated with user profiles.
Date
2026-04-03 00:00:00
Modified
None
Id
a65cfb85-180a-4343-9be8-5fc6f0afd7ff
Tags
attack.discovery attack.t1087.001
Type
Nextron Sigma feed only (private)
