Detection rules › Sigma

Base64 Encoded PowerShell Command Detected

Status
test
Severity
high
Log source
category process_creation, product windows
Author
Florian Roth (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string

Known false positives

  • Administrative script libraries

MITRE ATT&CK coverage

Telemetry coverage

Rule body

title: Base64 Encoded PowerShell Command Detected
id: e32d4572-9826-4738-b651-95fa63747e8a
status: test
description: Detects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string
references:
    - https://gist.github.com/Neo23x0/6af876ee72b51676c82a2db8d2cd3639
author: Florian Roth (Nextron Systems)
date: 2020-01-29
modified: 2023-01-26
tags:
    - attack.stealth
    - attack.t1027
    - attack.execution
    - attack.t1140
    - attack.t1059.001
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains: '::FromBase64String('
    condition: selection
falsepositives:
    - Administrative script libraries
level: high

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    CommandLine|contains: '::FromBase64String('

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • ::FromBase64String( corpus 2 (sigma 1, chronicle 1)
field:"CommandLine" kind:match value:"::FromBase64String("