Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
Alerts when a process uses NirCmd.exe PE metadata while the executable name is renamed to nircmd.exe or nircmdc.exe.
- Product
- windows
- Category
- process_creation
- Author
- X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2024-03-11
- Updated
- 2026-07-30
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation where the PE metadata field OriginalFileName is set to NirCmd.exe while the running image path/name ends with nircmd.exe or nircmdc.exe. Attackers may rename legitimate binaries to evade simple file-name based detections and blend into normal activity. The detection relies on process creation telemetry including the process image name/path and extracted PE metadata fields.
Reporting behind it
- microsoft.comhttps://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
- nirsoft.nethttps://www.nirsoft.net/utils/nircmd.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_nircmd.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
id: 68c862bc-2b88-4d1b-9270-827afdf77ed3
status: test
description: This rule flags Windows process creation where the PE metadata field OriginalFileName is set to NirCmd.exe while the running image path/name ends with nircmd.exe or nircmdc.exe. Attackers may rename legitimate binaries to evade simple file-name based detections and blend into normal activity. The detection relies on process creation telemetry including the process image name/path and extracted PE metadata fields.
references:
- https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
- https://www.nirsoft.net/utils/nircmd.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_nircmd.yml
author: X__Junior (Nextron Systems), Huntrule Team
date: 2024-03-11
tags:
- attack.execution
- attack.stealth
- attack.t1059
- attack.t1202
logsource:
category: process_creation
product: windows
detection:
selection:
OriginalFileName: NirCmd.exe
filter_main_img:
Image|endswith:
- \nircmd.exe
- \nircmdc.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 264982dc-dbad-4dce-b707-1e0d3e0f73d9
type: derived