Detection rules › By event
Microsoft-Windows-PowerShell Event ID 4103
Sigma (71)
- Active Directory Forest PowerShell class called from a non administrative host
- AD Groups Or Users Enumeration Using PowerShell - PoshModule
- Alternate PowerShell Hosts - PowerShell Module
- Bad Opsec Powershell Code Artifacts
- BitLocker server feature activation (PowerShell)
- BITS payload downloaded via PowerShell
- Clear PowerShell History - PowerShell Module
- DCOM lateral movement (via MMC20)
- DoT (DNS over TLS) activation (PowerShell)
- DSRM password changed (Reg via PowerShell)
- Encoded PowerShell payload deployed (PowerShell)
- Event log clear attempt (PowerShell)
- Event log cleared using Diagnostics (via PowerShell)
- Exchange transport agent installation artifacts (PowerShell)
- Firewall configuration enumerated (PowerShell)
- Firewall deactivation (PowerShell)
- Group discovery (PowerShell)
- HackTool - Evil-WinRm Execution - PowerShell Module
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
- Invoke-Obfuscation Via Stdin - PowerShell Module
- Invoke-Obfuscation Via Use Clip - PowerShell Module
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
- Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet
- LSASS credential dump with LSASSY (PowerShell)
- Malicious PowerShell Commandlets - PoshModule
- Malicious PowerShell Scripts - PoshModule
- Microsoft Defender critical security components disabled (PowerShell)
- Microsoft Defender default action changed to allow any threat (PowerShell)
- Microsoft Defender security components disabled (PowerShell)
- Microsoft Defender threat exclusion added (PowerShell)
- OpenSSH native server feature installation
- OpenSSH server firewall configuration on Windows (PowerShell)
- OpenSSH service activation on Windows
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes
- Potential Active Directory Enumeration Using AD Module - PsModule
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
- PowerShell Decompress Commands
- PowerShell Get Clipboard
- Print spooler privilege escalation via printer added (CVE-2020-1048)
- Remote PowerShell Session (PS Module)
- Service abuse with backdoored "command failure" (Reg via PowerShell)
- Service abuse with malicious ImagePath (Reg via PowerShell)
- Service creation (PowerShell)
- Service permissions hijacked for privileges abuse (PowerShell)
- Service permissions hijacked for privileges abuse (Reg via PowerShell)
- Suspicious Computer Machine Password by PowerShell
- Suspicious Get Information for SMB Share - PowerShell Module
- Suspicious Get Local Groups Information
- Suspicious Get-ADDBAccount Usage
- Suspicious PowerShell Download - PoshModule
- Suspicious PowerShell Invocations - Generic - PowerShell Module
- Suspicious PowerShell Invocations - Specific - PowerShell Module
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell)
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
- System time changed (PowerShell)
- Use Get-NetTCPConnection - PowerShell Module
- Vault credentials manager accessed
- VSS backup deletion via WMI (Powershell)
- Webserver IIS module installed (PowerShell)
- Webserver IIS module installed via GAC manipulation (PowerShell)
- Windows Subsystem for Linux (WSL) installation (PowerShell)
- WMI registration (PowerShell)
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
Splunk (111)
- Adfind Commands (PowerShell)
- Adfind Execution (PowerShell)
- Application Discovery - Windows (PowerShell)
- ATBroker.exe Execution (PowerShell)
- AutoHotkey Execution (PowerShell)
- BITSadmin Execution (PowerShell)
- Browser Started with Remote Debugging - Windows (PowerShell)
- Bypass or Unrestricted PowerShell Execution (PowerShell)
- Certutil File Download (PowerShell)
- Certutil Obfuscate_Encode Files (PowerShell)
- Command Line Homoglyphs - Windows (PowerShell)
- Command Line lsass request (PowerShell)
- Command Line Utility Added to Accessibility Features (PowerShell)
- Command-Line Interface Execution (PowerShell)
- Common Exchange Recon cmdlets (PowerShell)
- ComputerDefaults UAC Bypass (PowerShell)
- ConsentPromptBehaviorAdmin Registry Value Modified (PowerShell)
- Create_Modify Schtasks (PowerShell)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (PowerShell)
- DLL Concatenation (PowerShell)
- Domain Controller Enumeration via nltest (PowerShell)
- Dump File Identified (PowerShell)
- EnableLUA Registry Value Modified (PowerShell)
- Encoded Powershell Command (PowerShell)
- Esentutl Execution (PowerShell)
- ETW Trace Provider Modified - PowerShell (PowerShell)
- Exchange New Export Request (PowerShell)
- Exfiltration via curl.exe - Windows (PowerShell)
- Expand.exe Execution (PowerShell)
- File and Directory Discovery Output to File - Windows (PowerShell)
- File_Folder Hidden - Windows (PowerShell)
- Group Policy Editor Execution (PowerShell)
- hh.exe Execution (PowerShell)
- hh.exe Remote File Execution (PowerShell)
- Invoke-DCOM.ps1 - PowerShell (PowerShell)
- Invoke-Expression Command (PowerShell)
- Invoke-WebRequest Command (PowerShell)
- ISO Image Mounted - Windows (PowerShell)
- Known Process Injection Commands (PowerShell)
- LocalAccountTokenFilterPolicy Registry Value Modified (PowerShell)
- Locate Credentials (PowerShell)
- LSA Authentication Packages Registry Key Modified (PowerShell)
- masscan Execution - Windows (PowerShell)
- Modify Exchange Access Settings (PowerShell)
- MSHTA.exe execution (PowerShell)
- MSI Installation via Appcert (PowerShell)
- Network Share Connection Removal (PowerShell)
- New AutoRun Registry Key (PowerShell)
- ngen.exe File Download (PowerShell)
- Non-MSIExec .msi Installation (PowerShell)
- ntds.dit Command Line (PowerShell)
- Obfuscated Powershell Techniques (PowerShell)
- Output to File (PowerShell)
- Permission Groups Discovery: Domain Groups (PowerShell)
- Permission Groups Discovery: Local Groups (PowerShell)
- Possible Credential Dumping via Windows Network Providers (PowerShell)
- Potential AutoHotkey .ahk Execution (PowerShell)
- Potential fodhelper UAC Bypass Attempt (PowerShell)
- Potential LSA password filter (PowerShell)
- Potential Target Discovery via PowerShell Event Log Queries (PowerShell)
- PowerHuntShares Commands (PowerShell)
- PowerShell Clipboard Access (PowerShell)
- PowerShell CreateDecryptor (PowerShell)
- PowerShell Downgrade (PowerShell)
- PowerShell Download Activity (PowerShell)
- PowerShell DownloadFile_DownloadString (PowerShell)
- PowerShell Hidden Window (PowerShell)
- Powershell ICMP Data Exfiltration (PowerShell)
- PowerShell Modifying Registry Values (PowerShell)
- PowerShell XML Retrieval (PowerShell)
- PowerView_SharpView Commands (PowerShell)
- PromptOnSecureDesktop Registry Value Modified (PowerShell)
- ProtocolHandler.exe File Download (PowerShell)
- Proxy Execution via Appcert (PowerShell)
- Query Registry (PowerShell)
- Rclone Execution (PowerShell)
- RdrLeakDiag.exe Memory Dump (PowerShell)
- Read-Only Attribute Removed - Windows (PowerShell)
- Registry Entry Created - PowerShell (PowerShell)
- regsvr32 Execution (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote Admin Tools (PowerShell)
- Remote WMIC Query (PowerShell)
- Rundll32 Command Line (PowerShell)
- Scheduled Task with Potential SSH Tunnel - Windows (PowerShell)
- Security Software Discovery via Findstr.exe (PowerShell)
- Security Software Discovery via WMI (PowerShell)
- Sliver C2 Implant Activity Pattern (PowerShell)
- Startup Folder Location Modified - Windows (PowerShell)
- Stored Credentials from Web Browsers - Windows (PowerShell)
- Suspicious AteraAgent Installation - Windows (PowerShell)
- Suspicious DLLhost Execution (PowerShell)
- Suspicious Powershell (PowerShell)
- Suspicious PowerShell Clipboard Activity (PowerShell)
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious Registry Key Created (PowerShell)
- System Information Discovery - Windows (PowerShell)
- System Network Connections Discovery - Windows (PowerShell)
- System Owner_User Discovery - Windows (PowerShell)
- Timestamp Manipulation (PowerShell)
- User Discovery via Environment Variables - PowerShell (PowerShell)
- User_Domain Enumeration Tool - Windows (PowerShell)
- Visio.exe File Download (PowerShell)
- WebLogic CVE-2017-10271 (PowerShell)
- Windows - Service Stop (PowerShell)
- Windows Copy Files (PowerShell)
- Windows Firewall Rule Creation (PowerShell)
- Windows Process Copied from System Folder (PowerShell)
- WinLogon Registry Key Modified (PowerShell)
- Wow6432Node Classes Autorun Keys Modification (PowerShell)