Suspicious PowerShell Invocations - Generic - PowerShell Module
Detects suspicious PowerShell invocation command parameters
Detection logic
selection_encoded
ContextInfo|contains:
- " -enc "
- " -EncodedCommand "
- " -ec "selection_hidden
ContextInfo|contains:
- " -w hidden "
- " -window hidden "
- " -windowstyle hidden "
- " -w 1 "selection_noninteractive
ContextInfo|contains:
- " -noni "
- " -noninteractive "Condition
all of selection*Raw YAML
title: Suspicious PowerShell Invocations - Generic - PowerShell Module
id: bbb80e91-5746-4fbe-8898-122e2cafdbf4
related:
- id: 3d304fda-78aa-43ed-975c-d740798a49c1
type: derived
- id: ed965133-513f-41d9-a441-e38076a0798f
type: similar
status: test
description: Detects suspicious PowerShell invocation command parameters
references:
- Internal Research
author: Florian Roth (Nextron Systems)
date: 2017-03-12
modified: 2023-01-03
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_encoded:
ContextInfo|contains:
- ' -enc '
- ' -EncodedCommand '
- ' -ec '
selection_hidden:
ContextInfo|contains:
- ' -w hidden '
- ' -window hidden '
- ' -windowstyle hidden '
- ' -w 1 '
selection_noninteractive:
ContextInfo|contains:
- ' -noni '
- ' -noninteractive '
condition: all of selection*
falsepositives:
- Very special / sneaky PowerShell scripts
level: highFalse positives
- Very special / sneaky PowerShell scripts
References
Internal Research
Related rules
- derived3d304fda-78aa-43ed-975c-d740798a49c1
- similared965133-513f-41d9-a441-e38076a0798f
Similar rules
Alternate PowerShell Hosts - PowerShell Module
mediumwindows · Shares T1059
Bad Opsec Powershell Code Artifacts
criticalwindows · Shares T1059
Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
highwindows · Shares T1059
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
mediumwindows · Shares T1059