Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
Detects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
Detection logic
selection_img
- Image|endswith:
- \powershell.exe
- \pwsh.exe
- OriginalFileName:
- PowerShell.EXE
- pwsh.dllselection_cmdlet_namespace
CommandLine|contains: System.Security.Cryptography.selection_cmdlet_classes
CommandLine|contains:
- .AesCryptoServiceProvider
- .DESCryptoServiceProvider
- .DSACryptoServiceProvider
- .RC2CryptoServiceProvider
- .Rijndael
- .RSACryptoServiceProvider
- .TripleDESCryptoServiceProviderCondition
all of selection_*Raw YAML
title: Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
id: ad856965-f44d-42a8-945e-bbf7bd03d05a
status: test
description: |
Detects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace.
The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption.
These can be used for example in decrypting malicious payload for defense evasion.
references:
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography?view=net-8.0
- https://blogs.vmware.com/security/2023/11/jupyter-rising-an-update-on-jupyter-infostealer.html
- https://www.virustotal.com/gui/file/39102fb7bb6a74a9c8cb6d46419f9015b381199ea8524c1376672b30fffd69d2
author: Andreas Braathen (mnemonic.io)
date: 2023-12-01
tags:
- attack.execution
- attack.stealth
- attack.t1059.001
- attack.t1027.010
- detection.threat-hunting
logsource:
product: windows
category: process_creation
detection:
selection_img:
- Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- OriginalFileName:
- 'PowerShell.EXE'
- 'pwsh.dll'
selection_cmdlet_namespace:
CommandLine|contains: 'System.Security.Cryptography.'
selection_cmdlet_classes:
CommandLine|contains:
- '.AesCryptoServiceProvider'
- '.DESCryptoServiceProvider'
- '.DSACryptoServiceProvider'
- '.RC2CryptoServiceProvider'
- '.Rijndael'
- '.RSACryptoServiceProvider'
- '.TripleDESCryptoServiceProvider'
condition: all of selection_*
falsepositives:
- Classes are legitimately used, but less so when e.g. parents with low prevalence or decryption of content in temporary folders.
level: mediumFalse positives
- Classes are legitimately used, but less so when e.g. parents with low prevalence or decryption of content in temporary folders.
References
Similar rules
Obfuscated PowerShell MSI Install via WindowsInstaller COM
highwindows · Shares T1027, T1059
Base64 Encoded PowerShell Command Detected
highwindows · Shares T1027, T1059
ConvertTo-SecureString Cmdlet Usage Via CommandLine
mediumwindows · Shares T1027, T1059
HackTool - CrackMapExec PowerShell Obfuscation
highwindows · Shares T1059, T1027