Windows File Events: VBS gatherNetworkInfo results file creation

Flags Windows file writes under System32\config consistent with gatherNetworkInfo.vbs network reconnaissance output.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-02-08
Updated
2026-07-31

What it detects

This rule identifies file creation events for output artifacts associated with executing the built-in reconnaissance script C:\Windows\System32\gatherNetworkInfo.vbs. Attackers may run this script to quickly collect network configuration and state, then store results in specific files for later review. The detection relies on Windows file event telemetry matching TargetFilename paths under C:\Windows\System32\config with particular result filenames.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.