Windows nltest.exe Execution for Network Information Discovery

Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Arun Chauhan (SigmaHQ), DRL 1.1
Published
2023-02-03
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process creation events where nltest.exe is executed, including the specific Image ending with '\nltest.exe' and the OriginalFileName value 'nltestrk.exe'. Attackers commonly use nltest functionality to enumerate domain and network-related information during discovery. The detection relies on Windows process creation telemetry that includes the executable path/name and the OriginalFileName field.

Related detections9 linkedT1018 — drag to rearrange
Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
Uncommon Domain Trust Discovery via Nltest (via process_creation)
Suspicious Domain Controller and Trust Enumeration via Nltest
Windows Process Creation: Renamed AdFind.exe Executions
Windows nltest.exe Recon via Server Query and Domain Trust Enumeration
Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Cisco AAA discovery via show/dir commands
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
Suspicious Codepage Change Followed By Nltest Domain Trust Discovery
Windows nltest.exe Execution for Network Information Discovery
Pivot detection · T1018 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.