Rule Info
Name
Bulk Process Termination via PowerShell Whitelist Exclusion
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Tim Rauch (Nextron Systems)
Description
Detects PowerShell commands that enumerate all running processes and terminate those
not matching a hardcoded whitelist. This pattern is characteristic of ransomware and
destructive malware that kills security tools, backup agents, and database services
before payload execution.
Date
2026-09-30 00:00:00
Modified
None
Id
b59d39d5-b417-4f5f-a6c9-80c0c59c6430
Tags
attack.defense-impairment attack.t1685 attack.impact attack.t1489
Type
Nextron Sigma feed only (private)
