Bad Opsec Powershell Code Artifacts

 Original Source: [Sigma source]
Title: Bad Opsec Powershell Code Artifacts
Status: test
Description:focuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including Cobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads that often undergo minimal changes by attackers due to bad opsec.
References:
  -https://newtonpaul.com/analysing-fileless-malware-cobalt-strike-beacon/
  -https://labs.sentinelone.com/top-tier-russian-organized-cybercrime-group-unveils-fileless-stealthy-powertrick-backdoor-for-high-value-targets/
  -https://www.mdeditor.tw/pl/pgRt
Author: ok @securonix invrep_de, oscd.community
Date: 2020-10-09
modified:2022-12-25
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_module
  • definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
Detection:
  selection_4103:
    Payload|contains:
      -'$DoIt'
      -'harmj0y'
      -'mattifestation'
      -'_RastaMouse'
      -'tifkin_'
      -'0xdeadbeef'

  condition:selection_4103
Falsepositives:
  -Moderate-to-low; Despite the shorter length/lower entropy for some of these, because of high specificity, fp appears to be fairly limited in many environments.
Level: critical