Detection rules › Sigma

Suspicious PowerShell Parameter Substring

Status
test
Severity
high
Log source
category process_creation, product windows
Author
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix)
Source
github.com/SigmaHQ/sigma

Detects suspicious PowerShell invocation with a parameter substring

MITRE ATT&CK coverage

Telemetry coverage

Rule body

title: Suspicious PowerShell Parameter Substring
id: 36210e0d-5b19-485d-a087-c096088885f0
status: test
description: Detects suspicious PowerShell invocation with a parameter substring
references:
    - http://www.danielbohannon.com/blog-1/2017/3/12/powershell-execution-argument-obfuscation-how-it-can-make-detection-easier
author: Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix)
date: 2019-01-16
modified: 2022-07-14
tags:
    - attack.execution
    - attack.t1059.001
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\powershell.exe'
            - '\pwsh.exe'
        CommandLine|contains:
            - ' -windowstyle h '
            - ' -windowstyl h'
            - ' -windowsty h'
            - ' -windowst h'
            - ' -windows h'
            - ' -windo h'
            - ' -wind h'
            - ' -win h'
            - ' -wi h'
            - ' -win h '
            - ' -win hi '
            - ' -win hid '
            - ' -win hidd '
            - ' -win hidde '
            - ' -NoPr '
            - ' -NoPro '
            - ' -NoProf '
            - ' -NoProfi '
            - ' -NoProfil '
            - ' -nonin '
            - ' -nonint '
            - ' -noninte '
            - ' -noninter '
            - ' -nonintera '
            - ' -noninterac '
            - ' -noninteract '
            - ' -noninteracti '
            - ' -noninteractiv '
            - ' -ec '
            - ' -encodedComman '
            - ' -encodedComma '
            - ' -encodedComm '
            - ' -encodedCom '
            - ' -encodedCo '
            - ' -encodedC '
            - ' -encoded '
            - ' -encode '
            - ' -encod '
            - ' -enco '
            - ' -en '
            - ' -executionpolic '
            - ' -executionpoli '
            - ' -executionpol '
            - ' -executionpo '
            - ' -executionp '
            - ' -execution bypass'
            - ' -executio bypass'
            - ' -executi bypass'
            - ' -execut bypass'
            - ' -execu bypass'
            - ' -exec bypass'
            - ' -exe bypass'
            - ' -ex bypass'
            - ' -ep bypass'
            - ' /windowstyle h '
            - ' /windowstyl h'
            - ' /windowsty h'
            - ' /windowst h'
            - ' /windows h'
            - ' /windo h'
            - ' /wind h'
            - ' /win h'
            - ' /wi h'
            - ' /win h '
            - ' /win hi '
            - ' /win hid '
            - ' /win hidd '
            - ' /win hidde '
            - ' /NoPr '
            - ' /NoPro '
            - ' /NoProf '
            - ' /NoProfi '
            - ' /NoProfil '
            - ' /nonin '
            - ' /nonint '
            - ' /noninte '
            - ' /noninter '
            - ' /nonintera '
            - ' /noninterac '
            - ' /noninteract '
            - ' /noninteracti '
            - ' /noninteractiv '
            - ' /ec '
            - ' /encodedComman '
            - ' /encodedComma '
            - ' /encodedComm '
            - ' /encodedCom '
            - ' /encodedCo '
            - ' /encodedC '
            - ' /encoded '
            - ' /encode '
            - ' /encod '
            - ' /enco '
            - ' /en '
            - ' /executionpolic '
            - ' /executionpoli '
            - ' /executionpol '
            - ' /executionpo '
            - ' /executionp '
            - ' /execution bypass'
            - ' /executio bypass'
            - ' /executi bypass'
            - ' /execut bypass'
            - ' /execu bypass'
            - ' /exec bypass'
            - ' /exe bypass'
            - ' /ex bypass'
            - ' /ep bypass'
    condition: selection
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    Image|endswith:
        - '\powershell.exe'
        - '\pwsh.exe'
    CommandLine|contains:
        - ' -windowstyle h '
        - ' -windowstyl h'
        - ' -windowsty h'
        - ' -windowst h'
        - ' -windows h'
        - ' -windo h'
        - ' -wind h'
        - ' -win h'
        - ' -wi h'
        - ' -win h '
        - ' -win hi '
        - ' -win hid '
        - ' -win hidd '
        - ' -win hidde '
        - ' -NoPr '
        - ' -NoPro '
        - ' -NoProf '
        - ' -NoProfi '
        - ' -NoProfil '
        - ' -nonin '
        - ' -nonint '
        - ' -noninte '
        - ' -noninter '
        - ' -nonintera '
        - ' -noninterac '
        - ' -noninteract '
        - ' -noninteracti '
        - ' -noninteractiv '
        - ' -ec '
        - ' -encodedComman '
        - ' -encodedComma '
        - ' -encodedComm '
        - ' -encodedCom '
        - ' -encodedCo '
        - ' -encodedC '
        - ' -encoded '
        - ' -encode '
        - ' -encod '
        - ' -enco '
        - ' -en '
        - ' -executionpolic '
        - ' -executionpoli '
        - ' -executionpol '
        - ' -executionpo '
        - ' -executionp '
        - ' -execution bypass'
        - ' -executio bypass'
        - ' -executi bypass'
        - ' -execut bypass'
        - ' -execu bypass'
        - ' -exec bypass'
        - ' -exe bypass'
        - ' -ex bypass'
        - ' -ep bypass'
        - ' /windowstyle h '
        - ' /windowstyl h'
        - ' /windowsty h'
        - ' /windowst h'
        - ' /windows h'
        - ' /windo h'
        - ' /wind h'
        - ' /win h'
        - ' /wi h'
        - ' /win h '
        - ' /win hi '
        - ' /win hid '
        - ' /win hidd '
        - ' /win hidde '
        - ' /NoPr '
        - ' /NoPro '
        - ' /NoProf '
        - ' /NoProfi '
        - ' /NoProfil '
        - ' /nonin '
        - ' /nonint '
        - ' /noninte '
        - ' /noninter '
        - ' /nonintera '
        - ' /noninterac '
        - ' /noninteract '
        - ' /noninteracti '
        - ' /noninteractiv '
        - ' /ec '
        - ' /encodedComman '
        - ' /encodedComma '
        - ' /encodedComm '
        - ' /encodedCom '
        - ' /encodedCo '
        - ' /encodedC '
        - ' /encoded '
        - ' /encode '
        - ' /encod '
        - ' /enco '
        - ' /en '
        - ' /executionpolic '
        - ' /executionpoli '
        - ' /executionpol '
        - ' /executionpo '
        - ' /executionp '
        - ' /execution bypass'
        - ' /executio bypass'
        - ' /executi bypass'
        - ' /execut bypass'
        - ' /execu bypass'
        - ' /exec bypass'
        - ' /exe bypass'
        - ' /ex bypass'
        - ' /ep bypass'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • -NoPr
  • -NoPro
  • -NoProf
  • -NoProfi
  • -NoProfil
  • -ec corpus 2 (sigma 2)
  • -en corpus 5 (sigma 3, elastic 2)
  • -enco corpus 3 (elastic 2, sigma 1)
  • -encod corpus 3 (elastic 2, sigma 1)
  • -encode corpus 3 (elastic 2, sigma 1)
  • -encoded corpus 3 (elastic 2, sigma 1)
  • -encodedC
  • -encodedCo
  • -encodedCom
  • -encodedComm
  • -encodedComma
  • -encodedComman
  • -ep bypass
  • -ex bypass
  • -exe bypass
  • -exec bypass
  • -execu bypass
  • -execut bypass
  • -executi bypass
  • -executio bypass
  • -execution bypass
  • -executionp
  • -executionpo
  • -executionpol
  • -executionpoli
  • -executionpolic
  • -nonin
  • -nonint
  • -noninte
  • -noninter
  • -nonintera
  • -noninterac
  • -noninteract
  • -noninteracti
  • -noninteractiv
  • +68 more values (see full rule source)
field:"CommandLine" kind:match
Imageends_with
  • \powershell.exe corpus 179 (sigma 178, kusto 1)
  • \pwsh.exe corpus 165 (sigma 164, kusto 1)
field:"Image" kind:ends_with