Potential Remote PowerShell Session Initiated

 Original Source: [Sigma source]
Title: Potential Remote PowerShell Session Initiated
Status: test
Description:Detects a process that initiated a network connection over ports 5985 or 5986 from a non-network service account. This could potentially indicates a remote PowerShell connection.
References:
  -https://threathunterplaybook.com/hunts/windows/190511-RemotePwshExecution/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g
Date: 2019-09-12
modified:2024-02-02
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
  • -'attack.lateral-movement'
  • -'attack.t1021.006'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    DestinationPort:
      -'5985'
      -'5986'

    Initiated: 'true'
    SourceIsIpv6: 'false'
  filter_main_service_users:
    - User|contains:
      - 'NETWORK SERVICE'
      - 'NETZWERKDIENST'
      - 'SERVICIO DE RED'
      - 'SERVIZIO DI RETE'
    - User|contains|all:
      - 'SERVICE R'
      - 'SEAU'
  filter_main_localhost:
    SourceIp:
      -'::1'
      -'127.0.0.1'

    DestinationIp:
      -'::1'
      -'127.0.0.1'

  filter_optional_avast:
    Image:
      -'C:\Program Files\Avast Software\Avast\AvastSvc.exe'
      -'C:\Program Files (x86)\Avast Software\Avast\AvastSvc.exe'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Legitimate usage of remote PowerShell, e.g. remote administration and monitoring.
  -Network Service user name of a not-covered localization
Level: high