Inverted Windows System Path Strings in CommandLine

Rule Info

Name
Inverted Windows System Path Strings in CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects reversed/inverted strings of Windows system directory paths in command line arguments. Adversaries may reverse path strings to conceal references to system directories and bypass static string-based detection.
Reference
Internal Research
Date
2026-07-17 00:00:00
Modified
None
Id
c4a7e1f3-9b2d-4e8a-b5c6-1d3f0e7a9b2c
Tags
attack.execution attack.t1059.003 attack.stealth attack.t1027.010
Type
Nextron Sigma feed only (private)

Rule History