PowerShell File Discovery Activity in User Directories

Rule Info

Name
PowerShell File Discovery Activity in User Directories
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell scripts that enumerate specific files and directories in common user document folders, which may indicate data discovery for exfiltration.
Date
2025-09-25 00:00:00
Modified
None
Id
c955bb31-3108-4514-b69f-f528e613d877
Tags
attack.discovery attack.collection attack.t1083 attack.t1119 attack.t1005
Type
Nextron Sigma feed only (private)

Rule History