519 detection rules reference this event. View event page.Sigma (218)
- AADInternals PowerShell Cmdlets Execution - PsScript severity high
- Abuse of Service Permissions to Hide Services Via Set-Service - PS severity high T1574, T1574.011
- Access to Browser Login Data severity medium T1555, T1555.003
- Active Directory Computers Enumeration With Get-AdComputer severity low T1018, T1087, T1087.002
- Active Directory Forest PowerShell class called from a non administrative host severity medium T1482
- Active Directory Group Enumeration With Get-AdGroup severity low T1069, T1069.002
- AD Groups Or Users Enumeration Using PowerShell - ScriptBlock severity low T1069, T1069.001
- Add Windows Capability Via PowerShell Script severity medium
- AMSI Bypass Pattern Assembly GetType severity high T1685
- Automated Collection Bookmarks Using Get-ChildItem PowerShell severity low T1217
- Automated Collection Command PowerShell severity medium T1119
- BitLocker server feature activation (PowerShell) severity high T1486
- BITS payload downloaded via PowerShell severity medium T1048, T1105, T1197, T1570
- Certificate Exported Via PowerShell - ScriptBlock severity medium T1552, T1552.004
- Change PowerShell Policies to an Insecure Level - PowerShell severity medium T1059, T1059.001
- Change User Agents with WebRequest severity medium T1071, T1071.001
- Clear PowerShell History - PowerShell severity medium T1070, T1070.003
- Clearing Windows Console History severity high T1070, T1070.003
- Code Executed Via Office Add-in XLL File severity high T1137, T1137.006
- Compress-Archive Cmdlet Execution severity low T1560
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell severity medium T1033
- Create Volume Shadow Copy with Powershell severity high T1003, T1003.003
- DCOM lateral movement (via MMC20) severity high T1021, T1021.003
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script severity high T1490
- Detected Windows Software Discovery - PowerShell severity medium T1518
- DirectorySearcher Powershell Exploitation severity medium T1018
- Disable of ETW Trace - Powershell severity high T1070, T1685
- Disable Powershell Command History severity high T1070, T1070.003
- Disable-WindowsOptionalFeature Command PowerShell severity high T1685
- DMSA Link Attributes Modified severity low T1078, T1078.002, T1098
- DMSA Service Account Created in Specific OUs - PowerShell severity medium T1078, T1078.002, T1098
- Domain group membership change severity high T1098
- DoT (DNS over TLS) activation (PowerShell) severity medium T1071, T1071.004
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock severity high T1059, T1059.001
- DSRM password changed (Reg via PowerShell) severity high T1098
- Dump Credentials from Windows Credential Manager With PowerShell severity medium T1555
- Enable Windows Remote Management severity medium T1021, T1021.006
- Encoded PowerShell payload deployed (PowerShell) severity high T1027, T1059, T1059.001
- Enumerate Credentials from Windows Credential Manager With PowerShell severity medium T1555
- Event log clear attempt (PowerShell) severity high T1070, T1685.005
- Event log cleared using Diagnostics (via PowerShell) severity high T1070, T1685.005
- Exchange transport agent installation artifacts (PowerShell) severity high T1505, T1505.002
- Execute Invoke-command on Remote Host severity medium T1021, T1021.006
- Extracting Information with PowerShell severity medium T1552, T1552.001
- Firewall configuration enumerated (PowerShell) severity medium T1016
- Firewall deactivation (PowerShell) severity high T1685, T1686
- Get-ADUser Enumeration Using UserAccountControl Flags severity medium T1033
- Group discovery (PowerShell) severity medium T1069, T1069.001, T1069.002
- HackTool - Rubeus Execution - ScriptBlock severity high T1003, T1550, T1550.003, T1558, T1558.003
- HackTool - WinPwn Execution - ScriptBlock severity high T1046, T1082, T1106, T1518, T1548, T1548.002
- Import PowerShell Modules From Suspicious Directories severity medium T1059, T1059.001
- Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet severity medium T1114, T1114.003, T1564, T1564.008
- Invoke-Obfuscation CLIP+ Launcher - PowerShell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell severity medium T1027, T1059, T1059.001
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell severity medium T1027, T1059, T1059.001
- Invoke-Obfuscation STDIN+ Launcher - Powershell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation VAR+ Launcher - PowerShell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Stdin - Powershell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Use Clip - Powershell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Use MSHTA - PowerShell severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Use Rundll32 - PowerShell severity high T1027, T1059, T1059.001
- Lace Tempest PowerShell Evidence Eraser severity high T1059, T1059.001
- Lace Tempest PowerShell Launcher severity high T1059, T1059.001
- Live Memory Dump Using Powershell severity high T1003
- Local group membership change severity high T1098
- LSASS credential dump with LSASSY (PowerShell) severity medium T1003, T1003.001
- Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet severity medium T1020, T1114, T1114.003, T1564, T1564.008
- Malicious Nishang PowerShell Commandlets severity high T1059, T1059.001
- Malicious PowerShell Commandlets - ScriptBlock severity high T1059, T1059.001, T1069, T1069.001, T1069.002, T1087
- Malicious PowerShell Keywords severity medium T1059, T1059.001
- Malicious ShellIntel PowerShell Commandlets severity high T1059, T1059.001
- Manipulation of User Computer or Group Security Principals Across AD severity medium T1136, T1136.002
- Microsoft Defender critical security components disabled (PowerShell) severity high T1685
- Microsoft Defender default action changed to allow any threat (PowerShell) severity high T1685
- Microsoft Defender security components disabled (PowerShell) severity medium T1685
- Microsoft Defender threat exclusion added (PowerShell) severity high T1685
- Modify Group Policy Settings - ScriptBlockLogging severity medium T1484, T1484.001
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock severity low T1686, T1686.003
- NTFS Alternate Data Stream severity high T1059, T1059.001, T1564, T1564.004
- OpenSSH native server feature installation severity medium T1021, T1021.004
- OpenSSH server firewall configuration on Windows (PowerShell) severity high T1685, T1686
- OpenSSH service activation on Windows severity medium T1021, T1021.004
- Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy severity low T1201
- Payload downloaded via PowerShell severity high T1059, T1059.001, T1105
- PipeShell exfiltration over named pipes severity medium T1059, T1059.001
- Potential Active Directory Enumeration Using AD Module - PsScript severity medium
- Potential AMSI Bypass Script Using NULL Bits severity medium T1685
- Potential APT FIN7 POWERHOLD Execution severity high T1059, T1059.001
- Potential COM Objects Download Cradles Usage - PS Script severity medium T1105
- Potential Data Exfiltration Over SMTP Via Send-MailMessage Cmdlet severity medium T1048, T1048.003
- Potential Data Exfiltration Via Audio File severity medium
- Potential In-Memory Execution Using Reflection.Assembly severity medium T1620
- Potential Invoke-Mimikatz PowerShell Script severity high T1003
- Potential Keylogger Activity severity medium T1056, T1056.001
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock severity medium T1040
- Potential Persistence Via PowerShell User Profile Using Add-Content severity medium T1546, T1546.013
- Potential Persistence Via Security Descriptors - ScriptBlock severity high
- Potential PowerShell Obfuscation Using Alias Cmdlets severity low T1027, T1059, T1059.001
- Potential PowerShell Obfuscation Using Character Join severity low T1027, T1059, T1059.001
- Potential POWERTRASH Script Execution severity high T1059, T1059.001
- Potential Registry Reconnaissance Via PowerShell Script severity medium T1007, T1012
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock severity high T1218
- Potential Suspicious PowerShell Keywords severity medium T1059, T1059.001
- Potential Suspicious Windows Feature Enabled severity medium
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock severity medium T1018, T1558, T1589, T1589.002
- Potential WinAPI Calls Via PowerShell Scripts severity high T1059, T1059.001, T1106, T1620
- Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript severity medium
- Powershell Add Name Resolution Policy Table Rule severity high T1565
- PowerShell ADRecon Execution severity high T1059, T1059.001
- PowerShell Create Local User severity medium T1059, T1059.001, T1136, T1136.001
- Powershell Create Scheduled Task severity medium T1053, T1053.005
- PowerShell Credential Prompt severity high T1059, T1059.001
- PowerShell Deleted Mounted Share severity medium T1070, T1070.005
- Powershell Detect Virtualization Environment severity medium T1497, T1497.001
- Powershell Directory Enumeration severity medium T1083
- Powershell DNSExfiltration severity high T1048
- Powershell Execute Batch Script severity medium T1059, T1059.003
- PowerShell Get-Process LSASS in ScriptBlock severity high T1003, T1003.001
- PowerShell Hotfix Enumeration severity medium
- PowerShell ICMP Exfiltration severity medium T1048, T1048.003
- Powershell Install a DLL in System Directory severity high T1556, T1556.002
- Powershell Keylogging severity medium T1056, T1056.001
- Powershell Local Email Collection severity medium T1114, T1114.001
- Powershell LocalAccount Manipulation severity medium T1098
- Powershell MsXml COM Object severity medium T1059, T1059.001
- PowerShell PSAttack severity high T1059, T1059.001
- PowerShell Remote Session Creation severity medium T1059, T1059.001
- PowerShell Script Change Permission Via Set-Acl - PsScript severity low T1222
- PowerShell Script With File Hostname Resolving Capabilities severity medium T1020
- PowerShell Script With File Upload Capabilities severity low T1020
- Powershell Sensitive File Discovery severity medium T1083
- PowerShell Set-Acl On Windows Folder - PsScript severity high T1222
- PowerShell ShellCode severity high T1055, T1059, T1059.001
- Powershell Store File In Alternate Data Stream severity medium T1564, T1564.004
- Powershell Suspicious Win32_PnPEntity severity low T1120
- Powershell Timestomp severity medium T1070, T1070.006
- Powershell Token Obfuscation - Powershell severity medium T1027, T1027.009
- PowerShell Web Access Installation - PsScript severity high T1059, T1059.001
- Powershell WMI Persistence severity medium T1546, T1546.003
- PowerShell WMI Win32_Product Install MSI severity medium T1218, T1218.007
- PowerShell Write-EventLog Usage severity medium
- Powershell XML Execute Command severity medium T1059, T1059.001
- PowerView PowerShell Cmdlets - ScriptBlock severity high T1059, T1059.001
- Print spooler privilege escalation via printer added (CVE-2020-1048) severity high T1547, T1547.010
- PSAsyncShell - Asynchronous TCP Reverse Shell severity high T1059, T1059.001
- Recon Information for Export with PowerShell severity medium T1119
- Registry Modification Attempt Via VBScript - PowerShell severity medium T1059, T1059.005, T1112
- Registry-Free Process Scope COR_PROFILER severity medium T1574, T1574.012
- Remove Account From Domain Admin Group severity medium T1531
- Replace Desktop Wallpaper by Powershell severity low T1491, T1491.001
- Root Certificate Installed - PowerShell severity medium T1553, T1553.004
- Security Software Discovery Via Powershell Script severity medium T1518, T1518.001
- Service abuse with backdoored "command failure" (Reg via PowerShell) severity high T1543, T1543.003
- Service abuse with malicious ImagePath (Reg via PowerShell) severity high T1543, T1543.003
- Service creation (PowerShell) severity high T1543, T1543.003
- Service permissions hijacked for privileges abuse (PowerShell) severity high T1543, T1543.003, T1574, T1574.010
- Service permissions hijacked for privileges abuse (Reg via PowerShell) severity high T1543, T1543.003, T1574, T1574.010
- Service Registry Permissions Weakness Check severity medium T1574, T1574.011
- Silence.EDA Detection severity critical T1059, T1059.001, T1071, T1071.004, T1529, T1572
- SMB over QUIC Via PowerShell Script severity medium T1570
- Suspicious Connection to Remote Account severity low T1110, T1110.001
- Suspicious Eventlog Clear severity medium T1685, T1685.005
- Suspicious FromBase64String Usage On Gzip Archive - Ps Script severity medium T1132, T1132.001
- Suspicious Get Information for SMB Share severity low T1069, T1069.001
- Suspicious Get Local Groups Information - PowerShell severity low T1069, T1069.001
- Suspicious Get-ADReplAccount severity medium T1003, T1003.006
- Suspicious GetTypeFromCLSID ShellExecute severity medium T1546, T1546.015
- Suspicious GPO Discovery With Get-GPO severity low T1615
- Suspicious Hyper-V Cmdlets severity medium T1564, T1564.006
- Suspicious Invoke-Item From Mount-DiskImage severity medium T1553, T1553.005
- Suspicious IO.FileStream severity medium T1070, T1070.003
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock severity high T1558, T1558.003
- Suspicious Mount-DiskImage severity low T1553, T1553.005
- Suspicious New-PSDrive to Admin Share severity medium T1021, T1021.002
- Suspicious PowerShell Download - Powershell Script severity medium T1059, T1059.001
- Suspicious PowerShell Get Current User severity low T1033
- Suspicious PowerShell Invocations - Generic severity high T1059, T1059.001
- Suspicious PowerShell Invocations - Specific severity high T1059, T1059.001
- Suspicious PowerShell Mailbox Export to Share - PS severity critical
- Suspicious PowerShell WindowStyle Option severity medium T1564, T1564.003
- Suspicious Process Discovery With Get-Process severity low T1057
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS severity high T1574, T1574.011
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell) severity high T1087, T1087.002, T1558, T1558.003
- Suspicious SSL Connection severity low T1573
- Suspicious Start-Process PassThru severity medium T1036, T1036.003
- Suspicious TCP Tunnel Via PowerShell Script severity medium T1090
- Suspicious Unblock-File severity medium T1553, T1553.005
- Suspicious X509Enrollment - Ps Script severity medium T1553, T1553.004
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction severity medium T1218
- System time changed (PowerShell) severity medium T1070, T1070.006
- Tamper Windows Defender - ScriptBlockLogging severity high T1685
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging severity high T1685
- Testing Usage of Uncommonly Used Port severity medium T1571
- Troubleshooting Pack Cmdlet Execution severity medium T1202
- Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript severity medium
- Usage Of Web Request Commands And Cmdlets - ScriptBlock severity medium T1059, T1059.001
- Use Of Remove-Item to Delete File - ScriptBlock severity low T1070, T1070.004
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell severity medium T1033
- Vault credentials manager accessed severity high T1555, T1555.004
- Veeam Backup Servers Credential Dumping Script Execution severity high
- Vice Society directory crawling script for data exfiltration (via ps_script) severity high T1041, T1059, T1059.001
- VSS backup deletion via WMI (Powershell) severity high T1490
- Webserver IIS module installed (PowerShell) severity high T1505, T1505.004
- Webserver IIS module installed via GAC manipulation (PowerShell) severity high T1505, T1505.004
- WinAPI Function Calls Via PowerShell Scripts severity medium T1059, T1059.001, T1106
- WinAPI Library Calls Via PowerShell Scripts severity medium T1059, T1059.001, T1106
- Windows Defender Exclusions Added - PowerShell severity medium T1059, T1685
- Windows Firewall Profile Disabled severity medium T1686, T1686.003
- Windows Mail App Mailbox Access Via PowerShell Script severity medium T1070, T1070.008
- Windows Screen Capture with CopyFromScreen severity medium T1113
- Windows Subsystem for Linux (WSL) installation (PowerShell) severity medium T1564, T1564.006
- Winlogon Helper DLL severity medium T1547, T1547.004
- WMI registration (PowerShell) severity high T1546, T1546.003
- WMIC Unquoted Services Path Lookup - PowerShell severity medium T1047
- WMImplant Hack Tool severity high T1047, T1059, T1059.001
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script severity medium T1074, T1074.001
Elastic (14)
- Dynamic IEX Reconstruction via Method String Access severity low T1027, T1027.010, T1059, T1059.001, T1140
- Potential AMSI Bypass via RPC Runtime Hooking severity high T1059, T1059.001, T1685
- Potential Dynamic IEX Reconstruction via Environment Variables severity medium T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion severity high T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Character Array Reconstruction severity high T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation severity high T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via High Numeric Character Proportion severity low T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via High Special Character Proportion severity low building block T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Invalid Escape Sequences severity medium T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Reverse Keywords severity low T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via Special Character Overuse severity medium T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via String Concatenation severity high T1027, T1027.010, T1059, T1059.001, T1140
- Potential PowerShell Obfuscation via String Reordering severity medium T1027, T1027.010, T1059, T1059.001, T1140
- PowerShell Obfuscation via Negative Index String Reversal severity low T1027, T1027.010, T1059, T1059.001, T1140
Splunk (287)
- Access Common Package Config file (PowerShell) T1546
- Account Password Changed from Command Line - Windows (PowerShell) T1531
- Adfind Commands (PowerShell) T1016, T1018, T1069, T1069.002, T1087, T1087.002
- Adfind Execution (PowerShell) T1016, T1018, T1069, T1069.002, T1087, T1087.002
- AdsiSearcher Account Discovery severity medium T1087, T1087.002
- Allow Inbound Traffic In Firewall Rule severity medium T1021, T1021.001
- Application Discovery - Windows (PowerShell) T1518
- ATBroker.exe Execution (PowerShell) T1218
- Attempted Veeam Database Credential Dump (PowerShell) T1552, T1552.001
- AutoHotkey Execution (PowerShell) T1059
- AutoIt Execution (PowerShell) T1059
- BITSadmin Execution (PowerShell) T1048, T1048.003, T1105, T1197, T1570
- BitsAdmin NetCat PowerCat File Transfer (PowerShell) T1071, T1071.002, T1197
- Browser Started with Remote Debugging - Windows (PowerShell) T1185
- Bypass or Unrestricted PowerShell Execution (PowerShell) T1059, T1059.001
- Certutil File Download (PowerShell) T1027, T1105
- Certutil Obfuscate_Encode Files (PowerShell) T1027, T1132
- Clear Windows Event Logs (PowerShell) T1070, T1685.005
- CMD execution with _c (PowerShell) T1059, T1059.003
- Command Line Homoglyphs - Windows (PowerShell) T1027, T1027.010
- Command Line lsass request (PowerShell) T1003
- Common Active Directory Commands (PowerShell) T1007, T1087, T1087.002
- Common Exchange Recon cmdlets (PowerShell) T1059, T1059.001, T1087, T1087.003
- Common Reconnaissance Commands (PowerShell) T1007, T1033, T1057, T1059, T1059.003, T1059.004
- ComputerDefaults UAC Bypass (PowerShell) T1548, T1548.002
- ConsentPromptBehaviorAdmin Registry Value Modified (PowerShell) T1548, T1548.002
- Create_Modify Schtasks (PowerShell) T1053, T1053.005
- CSVDE Export Active Directory (PowerShell) T1087, T1087.001, T1087.002
- Data Staged to File (PowerShell) T1074, T1074.001
- Defender Registry Values Modified (PowerShell) T1112, T1685
- Delete ShadowCopy With PowerShell severity medium T1490
- Detect Certify With PowerShell Script Block Logging severity medium T1059, T1059.001, T1649
- Detect Copy of ShadowCopy with Script Block Logging severity medium T1003, T1003.002
- Detect Empire with PowerShell Script Block Logging severity medium T1059, T1059.001
- Detect Mimikatz With PowerShell Script Block Logging severity medium T1003, T1059, T1059.001
- Disabled Kerberos Pre-Authentication Discovery With Get-ADUser severity medium T1558, T1558.004
- Disabled Kerberos Pre-Authentication Discovery With PowerView severity medium T1558, T1558.004
- Disabled Pre-Authentication Accounts Discovery - PowerShell (PowerShell) T1087, T1133
- DLL Called with RS32 (PowerShell) T1218, T1218.011
- DLL Called with Uncommon Function (PowerShell) T1218, T1218.011
- DLL Concatenation (PowerShell) T1027, T1027.001, T1036
- DLL Execution from Uncommon Process (PowerShell) T1218, T1218.011
- DLLRegisterServer Called from Command Line (PowerShell) T1218, T1218.011
- Domain Controller Enumeration via nltest (PowerShell) T1016, T1018
- Domain Group Discovery with Adsisearcher severity medium T1069, T1069.002
- Domain Trust Discovery Commands - Windows (PowerShell) T1482
- Dump File Identified (PowerShell) T1003
- Elevated Group Discovery with PowerView T1069, T1069.002
- EnableLUA Registry Value Modified (PowerShell) T1548, T1548.002
- Encoded Powershell Command (PowerShell) T1027, T1059, T1059.001
- Esentutl Execution (PowerShell) T1003, T1003.002, T1003.003, T1105, T1564, T1570
- ETW Trace Provider Modified - PowerShell (PowerShell) T1070, T1685
- Event Logs Queried for RDP Sessions (PowerShell) T1082
- Exchange New Export Request (PowerShell) T1114, T1114.001, T1114.002
- Exchange PowerShell Module Usage severity medium T1059, T1059.001
- Executable Create Script Process (PowerShell) T1020, T1059, T1059.003, T1119
- Executable Process from Suspicious Folder (PowerShell) T1059, T1059.005, T1059.007, T1204, T1218, T1218.011
- Exfiltration via curl.exe - Windows (PowerShell) T1048
- Expand.exe Execution (PowerShell) T1105, T1564, T1564.004
- File and Directory Discovery Output to File - Windows (PowerShell) T1083
- File_Folder Hidden - Windows (PowerShell) T1222, T1222.001
- Get ADDefaultDomainPasswordPolicy with Powershell Script Block T1201
- Get ADUser with PowerShell Script Block T1087, T1087.002
- Get ADUserResultantPasswordPolicy with Powershell Script Block severity medium T1201
- Get DomainPolicy with Powershell Script Block severity medium T1201
- Get DomainUser with PowerShell Script Block severity medium T1087, T1087.002
- Get WMIObject Group Discovery with Script Block Logging T1069, T1069.001
- Get-DomainTrust with PowerShell Script Block severity medium T1482
- Get-ForestTrust with PowerShell Script Block severity medium T1059, T1059.001, T1482
- GetAdComputer with PowerShell Script Block T1018
- GetAdGroup with PowerShell Script Block T1069, T1069.002
- GetCurrent User with PowerShell Script Block T1033
- GetDomainComputer with PowerShell Script Block severity medium T1018
- GetDomainController with PowerShell Script Block severity medium T1018
- GetDomainGroup with PowerShell Script Block severity medium T1069, T1069.002
- GetLocalUser with PowerShell Script Block T1059, T1059.001, T1087, T1087.001
- GetNetTcpconnection with PowerShell Script Block T1049
- GetWmiObject Ds Computer with PowerShell Script Block severity medium T1018
- GetWmiObject Ds Group with PowerShell Script Block severity medium T1069, T1069.002
- GetWmiObject DS User with PowerShell Script Block severity medium T1087, T1087.002
- GetWmiObject User Account with PowerShell Script Block T1059, T1059.001, T1087, T1087.001
- Git Clone Repository (PowerShell) T1105
- Go Run Execution (PowerShell) T1059
- Group Policy Editor Execution (PowerShell) T1218, T1218.014
- hh.exe Execution (PowerShell) T1218, T1218.001
- hh.exe Remote File Execution (PowerShell) T1218, T1218.001
- High Entropy Powershell (PowerShell) T1059, T1059.001
- HTTP_HTTPS Default Security Zone Modified to Local Machine (PowerShell) T1112
- Impacket atexec.py Execution (PowerShell) T1027, T1053, T1053.005, T1059, T1059.003
- Interactive Session on Remote Endpoint with PowerShell severity medium T1021, T1021.006
- Invoke-DCOM.ps1 - PowerShell (PowerShell) T1021, T1021.003
- Invoke-Expression Command (PowerShell) T1059, T1059.001
- Invoke-WebRequest Command (PowerShell) T1059, T1059.001, T1105
- ISO Image Mounted - Windows (PowerShell) T1204, T1204.002, T1553, T1553.005
- Kerberos Pre-Authentication Flag Disabled with PowerShell severity medium T1558, T1558.004
- Known Process Injection Commands (PowerShell) T1055
- LocalAccountTokenFilterPolicy Registry Value Modified (PowerShell) T1112, T1550, T1550.002
- Locate Credentials (PowerShell) T1552, T1552.001
- Logon Script Registry Key added (PowerShell) T1037, T1037.001
- LSA Authentication Packages Registry Key Modified (PowerShell) T1547, T1547.002
- Mailsniper Invoke functions severity medium T1114, T1114.001
- masscan Execution - Windows (PowerShell) T1046
- Modify Exchange Access Settings (PowerShell) T1059, T1059.001
- Modify Windows Defender (PowerShell) T1685
- mshta.exe File Download (PowerShell) T1105, T1218, T1218.005
- MSI Installation via Appcert (PowerShell) T1218, T1218.007
- Native Archive Commands (PowerShell) T1074, T1074.001, T1560
- Network Share Connection Removal (PowerShell) T1070, T1070.005
- New AutoRun Registry Key (PowerShell) T1547, T1547.001
- ngen.exe File Download (PowerShell) T1105
- ngrok Execution - Windows (PowerShell) T1572
- NirCmd Execution (PowerShell) T1059, T1070, T1113
- NMAP Execution (PowerShell) T1018
- Non-MSIExec .msi Installation (PowerShell) T1059
- ntds.dit Command Line (PowerShell) T1003, T1003.003
- Output to File (PowerShell) T1036, T1059, T1059.003, T1074, T1074.001
- Package installation (PowerShell) T1105
- Permission Groups Discovery: Domain Groups (PowerShell) T1069, T1069.002
- Permission Groups Discovery: Local Groups (PowerShell) T1069
- Permissions Replaced by icacls - Windows (PowerShell) T1222, T1222.001
- Possible Credential Dumping via Windows Network Providers (PowerShell) T1003, T1112
- Potential AutoHotkey .ahk Execution (PowerShell) T1059
- Potential Cryptomining Commands (PowerShell) T1496
- Potential fodhelper UAC Bypass Attempt (PowerShell) T1548, T1548.002
- Potential LSA password filter (PowerShell) T1547, T1547.002, T1556, T1556.002
- Potential Proxy Malware via AutoRun Key (PowerShell) T1059, T1059.001, T1547, T1547.001
- Potential Sysinternals Tool Execution (PowerShell) T1218
- Potential Target Discovery via PowerShell Event Log Queries (PowerShell) T1082
- PowerShell 4104 Hunting T1059, T1059.001
- PowerShell Clipboard Access (PowerShell) T1059, T1059.001
- Powershell COM Hijacking InprocServer32 Modification severity medium T1059, T1059.001, T1546, T1546.015
- PowerShell CreateDecryptor (PowerShell) T1027, T1059, T1059.001
- Powershell Creating Thread Mutex severity medium T1027, T1027.005, T1059, T1059.001
- Powershell DLL_EXE Injection (PowerShell) T1055, T1055.001
- PowerShell Domain Enumeration severity low T1059, T1059.001
- PowerShell Downgrade (PowerShell) T1059, T1059.001, T1059.003
- PowerShell Download Activity (PowerShell) T1059, T1059.001, T1105
- PowerShell DownloadFile_DownloadString (PowerShell) T1059, T1059.001, T1105
- PowerShell Enable PowerShell Remoting severity low T1059, T1059.001
- Powershell Enable SMB1Protocol Feature severity medium T1027, T1027.005
- PowerShell Environment Variable Execution severity low T1059, T1059.001
- Powershell Execute COM Object severity medium T1059, T1059.001, T1546, T1546.015
- Powershell Fileless Process Injection via GetProcAddress severity medium T1055, T1059, T1059.001
- Powershell Fileless Script Contains Base64 Encoded Content severity medium T1027, T1059, T1059.001
- Powershell Get LocalGroup Discovery with Script Block Logging T1069, T1069.001
- PowerShell Hidden Window (PowerShell) T1059, T1564, T1564.003
- PowerShell Invoke CIMMethod CIMSession severity low T1047
- PowerShell Invoke WmiExec Usage severity medium T1047
- Powershell Load Module in Meterpreter severity medium T1059, T1059.001
- PowerShell Loading DotNET into Memory via Reflection severity low T1059, T1059.001
- PowerShell Modifying Registry Values (PowerShell) T1059, T1059.001, T1112
- PowerShell PInvoke Process Injection API Chain severity medium T1055, T1055.001, T1055.003, T1055.004, T1055.012, T1055.013
- Powershell Processing Stream Of Data severity low T1059, T1059.001
- Powershell Remote Services Add TrustedHost severity medium T1021, T1021.006
- Powershell Remove Windows Defender Directory severity low T1685
- PowerShell Script Block With URL Chain severity medium T1059, T1059.001, T1105
- PowerShell Script Keylogger (PowerShell) T1056, T1056.001, T1059, T1059.001
- PowerShell Start or Stop Service severity low T1059, T1059.001
- Powershell Using memory As Backing Store severity medium T1059, T1059.001
- PowerShell WebRequest Using Memory Stream severity medium T1027, T1027.011, T1059, T1059.001, T1105
- Powershell Windows Defender Exclusion Commands severity low T1685
- PowerShell XML Retrieval (PowerShell) T1059, T1059.001
- Powersploit SPN Enumeration (PowerShell) T1558, T1558.003
- PowerView_SharpView Commands (PowerShell) T1033, T1049, T1059, T1059.001, T1069, T1069.002
- PromptOnSecureDesktop Registry Value Modified (PowerShell) T1548, T1548.002
- ProtocolHandler.exe File Download (PowerShell) T1105
- Proxy Execution via Appcert (PowerShell) T1127
- PuTTY Secure Copy Client Execution (PowerShell) T1048
- QEMU Network Tunneling - Windows (PowerShell) T1095, T1572
- Query Registry (PowerShell) T1012
- Rclone Execution (PowerShell) T1030, T1048, T1048.003, T1567, T1567.002
- RDP Enabled (PowerShell) T1021, T1021.001, T1112
- RdrLeakDiag.exe Memory Dump (PowerShell) T1003, T1003.001
- Read-Only Attribute Removed - Windows (PowerShell) T1222, T1222.001
- Recon AVProduct Through Pwh or WMI severity medium T1592
- Recon Using WMI Class severity low T1059, T1059.001, T1592
- Registry Entry Created - PowerShell (PowerShell) T1112
- regsvr32 Execution (PowerShell) T1218, T1218.010
- Remote .msi Installation (PowerShell) T1218, T1218.007
- Remote .msi Installation (PowerShell) T1218, T1218.007
- Remote Admin Tools (PowerShell) T1021, T1059, T1059.003, T1569, T1569.002, T1570
- Remote Process Instantiation via DCOM and PowerShell Script Block severity medium T1021, T1021.003
- Remote Process Instantiation via WinRM and PowerShell Script Block severity medium T1021, T1021.006
- Remote Process Instantiation via WMI and PowerShell Script Block severity medium T1047
- Remote Share Directory Listing - Windows (PowerShell) T1083
- Remote System Discovery with Adsisearcher severity medium T1018
- Remote WMIC Query (PowerShell) T1047
- Rubeus Commands (PowerShell) T1558, T1558.001, T1558.002, T1558.003
- Rundll32 Command Line (PowerShell) T1218, T1218.011
- Rundll32 Suspicious Command Line (PowerShell) T1218, T1218.011
- rundll32.exe Executing DLL from Non-standard Directory (PowerShell) T1218, T1218.011
- Scheduled Task with Potential SSH Tunnel - Windows (PowerShell) T1053, T1572
- Security Software Discovery via Findstr.exe (PowerShell) T1518, T1518.001
- Security Software Discovery via WMI (PowerShell) T1518, T1518.001
- Service Stop Commands (PowerShell) T1489, T1685
- ServicePrincipalNames Discovery with PowerShell severity medium T1558, T1558.003
- SharpHound Keywords (PowerShell) T1069, T1069.001, T1069.002, T1082, T1087, T1087.001
- Shortcut Created in Startup Folder - Windows (PowerShell) T1547, T1547.001
- Sliver C2 Implant Activity Pattern (PowerShell) T1059
- Startup Folder Location Modified - Windows (PowerShell) T1547, T1547.001
- Stored Credentials from Web Browsers - Windows (PowerShell) T1555, T1555.003
- Suspicious DLLhost Execution (PowerShell) T1546, T1546.015
- Suspicious ntds.dit Commands (PowerShell) T1003, T1003.003
- Suspicious PowerShell Clipboard Activity (PowerShell) T1059, T1059.001, T1115
- Suspicious PowerShell Parameter Substring (PowerShell) T1059, T1059.001
- Suspicious reCAPTCHA Command Line (PowerShell) T1059, T1218
- Suspicious Registry Key Created (PowerShell) T1546, T1546.012, T1547, T1547.001
- Symbolic OR Hard File Link Created (PowerShell) T1204, T1204.002, T1547, T1547.009
- System Information Discovery - Windows (PowerShell) T1082
- System Network Connections Discovery - Windows (PowerShell) T1049
- System Owner_User Discovery - Windows (PowerShell) T1033
- Timestamp Manipulation (PowerShell) T1070, T1070.006
- Tunneling Process Created (PowerShell) T1095, T1572
- Unloading AMSI via Reflection severity medium T1059, T1059.001, T1685
- User Discovery via Environment Variables - PowerShell (PowerShell) T1033
- User Discovery With Env Vars PowerShell Script Block T1033
- User_Domain Enumeration Tool - Windows (PowerShell) T1087, T1087.002, T1136, T1136.002
- Utility Archive Data (PowerShell) T1560, T1560.001
- Visio.exe File Download (PowerShell) T1105
- Visual Studio Code Tunnel Execution (PowerShell) T1071, T1071.001
- WDigest Forced Credential Caching (PowerShell) T1003, T1003.005, T1112
- Windows - Service Stop (PowerShell) T1489, T1685
- Windows Account Discovery for None Disable User Account T1087, T1087.001
- Windows Account Discovery for Sam Account Name severity low T1087
- Windows Account Discovery With NetUser PreauthNotRequire T1087
- Windows Archive Collected Data via Powershell severity low T1560
- Windows Azure PowerShell Module Installation Via PowerShell Script severity medium T1021, T1021.007, T1069, T1069.003, T1078, T1098
- Windows ClipBoard Data via Get-ClipBoard severity low T1115
- Windows Cobalt Strike PowerShell Loader severity medium T1059, T1059.001, T1608
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script severity medium T1071, T1071.001, T1078, T1212, T1482
- Windows Copy Files (PowerShell) T1005, T1039, T1059
- Windows Default Cobalt Strike PowerShell Beacon severity medium T1059, T1059.001, T1204, T1204.002
- Windows Defender Disabled Detection (PowerShell) T1685
- Windows Domain Account Discovery Via Get-NetComputer severity low T1087, T1087.002
- Windows Enable PowerShell Web Access severity medium T1059, T1059.001
- Windows ESX Admins Group Creation via PowerShell severity medium T1136, T1136.001, T1136.002
- Windows Exfiltration Over C2 Via Invoke RestMethod severity medium T1041
- Windows Exfiltration Over C2 Via Powershell UploadString severity medium T1041
- Windows File Share Discovery With Powerview severity medium T1135
- Windows Find Domain Organizational Units with GetDomainOU severity medium T1087, T1087.002
- Windows Find Interesting ACL with FindInterestingDomainAcl severity medium T1087, T1087.002
- Windows Firewall Disabled (PowerShell) T1685, T1686
- Windows Firewall Rule Creation (PowerShell) T1685, T1686
- Windows Forest Discovery with GetForestDomain severity medium T1087, T1087.002
- Windows FTP Exfiltration (PowerShell) T1048, T1071, T1071.002
- Windows Gather Victim Host Information Camera severity low T1592, T1592.001
- Windows Get Local Admin with FindLocalAdminAccess severity medium T1087, T1087.002
- Windows Get-AdComputer Unconstrained Delegation Discovery severity medium T1018
- Windows LAPS Password Gathering Via PowerShell Script severity low T1003, T1552
- Windows Level RMM PowerShell Script Installer severity low T1219
- Windows Linked Policies In ADSI Discovery severity low T1087, T1087.002
- Windows PowerShell Add Module to Global Assembly Cache severity medium T1505, T1505.004
- Windows Powershell Commands from DNS TXT severity low T1059, T1059.001, T1071, T1071.004
- Windows Powershell Cryptography Namespace severity low T1059, T1059.001
- Windows PowerShell Disable HTTP Logging severity medium T1505, T1505.004, T1685, T1685.001
- Windows PowerShell Export Certificate severity low T1552, T1552.004, T1649
- Windows PowerShell Export PfxCertificate severity low T1552, T1552.004, T1649
- Windows PowerShell Get CIMInstance Remote Computer severity low T1059, T1059.001
- Windows Powershell History File Deletion severity low T1059, T1059.003, T1070, T1070.003
- Windows PowerShell IIS Components WebGlobalModule Usage severity low T1505, T1505.004
- Windows Powershell Import Applocker Policy severity low T1059, T1059.001, T1685
- Windows PowerShell Invoke-RestMethod IP Information Collection severity low T1016, T1059, T1059.001, T1082
- Windows PowerShell Invoke-Sqlcmd Execution T1059, T1059.001, T1059.003
- Windows Powershell Logoff User via Quser severity low T1059, T1059.001, T1531
- Windows PowerShell MSIX Package Installation severity medium T1059, T1059.001, T1547, T1547.001
- Windows PowerShell ScheduleTask severity low T1053, T1053.005, T1059, T1059.001
- Windows PowerShell Script Block With Malicious String severity medium T1059, T1059.001
- Windows PowerShell Script TabExpansion Direct Call severity low T1059, T1059.001, T1129
- Windows PowerShell WMI Win32 ScheduledJob severity medium T1059, T1059.001
- Windows PowerSploit GPP Discovery severity medium T1552, T1552.006
- Windows PowerView AD Access Control List Enumeration severity medium T1069, T1078, T1078.002
- Windows PowerView Constrained Delegation Discovery severity medium T1018
- Windows PowerView Kerberos Service Ticket Request severity medium T1558, T1558.003
- Windows PowerView SPN Discovery severity medium T1558, T1558.003
- Windows PowerView Unconstrained Delegation Discovery severity medium T1018
- Windows Process Copied from System Folder (PowerShell) T1036, T1036.003
- Windows Root Domain linked policies Discovery severity low T1087, T1087.002
- Windows Screen Capture Via Powershell severity medium T1113
- Windows Service Started (PowerShell) T1569, T1569.002
- Windows Software Discovery Via PowerShell severity low T1012, T1059, T1059.001, T1518
- Windows WinPEAS PowerShell Script Execution severity medium T1007, T1016, T1033, T1082, T1590, T1592
- WinLogon Registry Key Modified (PowerShell) T1547, T1547.004
- WinRM Tools (PowerShell) T1021, T1021.006, T1047
- WMI Recon Running Process Or Services severity low T1592
- WMIC Host Reconniassance (PowerShell) T1047, T1082
- Wow6432Node Classes Autorun Keys Modification (PowerShell) T1547, T1547.001
- Wscript_Cscript Execution (PowerShell) T1059, T1059.005, T1059.007