
Rule Info
Name
TXT File Association Hijacking
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects registry modifications that hijack the default handler for .txt files.
This technique is used by attackers to establish persistence by executing malicious code whenever a user opens a text file.
Date
2025-09-08 00:00:00
Modified
None
Id
d0563880-5465-40c2-9f3d-b570c89f2ca5
Tags
attack.persistence attack.t1546.001
Type
Nextron Sigma feed only (private)