PowerShell Download Via Net.WebClient - PowerShell Classic

 Original Source: [Sigma source]
Title: PowerShell Download Via Net.WebClient - PowerShell Classic
Status: test
Description:Detects PowerShell download activity, via the .DownloadFile() or .DownloadString() methods of the Net.WebClient class. This technique is often abused by attackers to download additional payloads.
References:
  -https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
Author: Florian Roth (Nextron Systems)
Date: 2017-03-05
modified:2026-04-28
Tags:
  • -'attack.execution'
  • -'attack.command-and-control'
  • -'attack.t1059.001'
  • -'attack.t1105'
Logsource:
  • product: windows
  • category: ps_classic_start
Detection:
  selection_webclient:
    Data|contains: 'Net.WebClient'
  selection_download:
    Data|contains:
      -'.DownloadFile('
      -'.DownloadString('

  condition:all of selection_*
Falsepositives:
  -This activity may be used by legitimate software, such as patch management tools or software updaters. Investigate any such activity and apply the necessary filter.
Level: low