Rule Info
Name
Potential RID Hijacking Attempt via PowerShell
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects PowerShell scripts that attempt to modify the SAM registry to potentially perform RID hijacking attacks.
In a RID hijacking attack, an attacker modifies the RID set of a user account like guest user to escalate privileges or impersonate another user.
Date
2026-05-19 00:00:00
Modified
None
Id
b016b61b-73fa-4ab4-9056-6fa49ef0931d
Tags
attack.persistence attack.privilege-escalation attack.t1098
Type
Nextron Sigma feed only (private)
