Rule Info
Name
Inverted Malware-Abused Path Strings in CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects reversed/inverted strings of writable Windows directories commonly abused
by malware as staging, persistence, or execution locations. Adversaries may reverse
path strings to bypass static path-based detection signatures.
Reference
Internal Research
Date
2026-07-17 00:00:00
Modified
None
Id
b8e4a6f2-3c7d-4b1e-8a5f-6d9c2f0e7b4a
Tags
attack.execution attack.t1059.003 attack.stealth attack.t1027.010
Type
Nextron Sigma feed only (private)
