Suspicious Bazar Network Reconnaissance Command Batch

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-04
Updated
2026-10-04

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the net.exe view-all-shares enumeration used in the Bazar and Cobalt Strike recon batch executed by Trickbot, Qbot and Hancitor crews after landing on a host. The operator sweeps for reachable systems and shares to select lateral-movement targets. Combined with adjacent systeminfo and whoami calls this pattern marks the start of hands-on-keyboard activity.

Related detections9 linkedT1057 — drag to rearrange
Suspicious Privilege Discovery Spawned by M365 Copilot Process
Suspicious Security Product Enumeration via tasklist
Suspicious node.exe Spawning tasklist Process Enumeration
Suspicious Virtual Machine Detection via WMI Win32_Process Query (via process_creation)
Possible Local Group Membership Enumeration via Security Event 4798
Antivirus Software Discovery via tasklist and findstr
Suspicious Security Software Discovery via tasklist and findstr (via process_creation)
Suspicious Security Process Enumeration via Tasklist And Findstr
Suspicious Active Directory Discovery via ADFind
Suspicious Bazar Network Reconnaissance Command Batch
Pivot detection · T1057 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.