Suspicious XOR Encoded PowerShell Command Line - PowerShell

 Original Source: [Sigma source]
Title: Suspicious XOR Encoded PowerShell Command Line - PowerShell
Status: test
Description:Detects suspicious powershell process which includes bxor command, alternative obfuscation method to b64 encoded commands.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=46
Author: Teymur Kheirkhabarov, Harish Segar (rule)
Date: 2020-06-29
modified:2023-10-27
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_classic_start
Detection:
  selection:
    Data|contains: 'HostName=ConsoleHost'
  filter:
    Data|contains:
      -'bxor'
      -'char'
      -'join'

  condition:selection and filter
Falsepositives:
  -Unknown
Level: medium