Suspicious ipconfig Reconnaissance Output Redirected to CentreStack Log File

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-29
Updated
2026-09-29

ATT&CK techniques

Discovery → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects ipconfig network reconnaissance whose output is redirected into a CentreStac_log.txt file under ProgramData, a marker observed after Gladinet CentreStack and Triofox exploitation. The attacker collects host network configuration and stages it to a staging file for later collection. The specific filename and redirect pattern make this a high confidence indicator of hands-on-keyboard activity.

Related detections9 linkedT1005 — drag to rearrange
Possible osTicket PHP Filter Chain Injection via Anonymous Ticket Endpoints (via webserver)
Suspicious Contagious Interview Exfiltration via Axios Upload User Agent
Suspicious Browser History Dumping via NirSoft Tool via process_creation
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Possible Local File Inclusion Path Traversal Targeting CentreStack Web.config
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious ipconfig Reconnaissance Output Redirected to CentreStack Log File
Pivot detection · T1005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.