Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts

Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-08
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows file creation events consistent with NetExec (nxc.exe) execution on a local host. It looks for a combination of execution-related content in the image path and on-disk PyInstaller extraction under the Temp directory, specifically including the extracted _MEI* folder and the nxc\data subdirectory. These extracted files are strong on-disk indicators because they are produced during NetExec startup as it unpacks embedded data to a temporary directory.

Related detections9 linkedT1059.005 — drag to rearrange
Suspicious Ransomware Fan-Out Deployment via PsExec Spread (Qilin)
Suspicious Impacket smbexec Command Execution Pattern
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Malicious PathWiper Loader Script Execution from Windows Temp via WScript
Malicious Impacket Wmiexec Remote Command Execution Pattern
Suspicious Remote Admin Share Execution via Conhost
Suspicious Office Application Spawning Script Or Shell Interpreter
Malicious Script Host Spawning PowerShell With Invoke-Expression (via process_creation)
Suspicious MSHTA VBScript WScript Shell Execution
Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Pivot detection · T1059.005 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.