Security Software Discovery Via Powershell Script

 Original Source: [Sigma source]
Title: Security Software Discovery Via Powershell Script
Status: test
Description:Detects calls to "get-process" where the output is piped to a "where-object" filter to search for security solution processes. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as firewall rules and anti-virus
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1518.001/T1518.001.md#atomic-test-2---security-software-discovery---powershell
Author: frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-12-16
modified:2023-10-24
Tags:
  • -'attack.discovery'
  • -'attack.t1518.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_cmdlet:
    ScriptBlockText|contains:
      -'get-process | \?'
      -'get-process | where'
      -'gps | \?'
      -'gps | where'

  selection_field:
    ScriptBlockText|contains:
      -'Company -like'
      -'Description -like'
      -'Name -like'
      -'Path -like'
      -'Product -like'

  selection_keywords:
    ScriptBlockText|contains:
      -'\*avira\*'
      -'\*carbonblack\*'
      -'\*cylance\*'
      -'\*defender\*'
      -'\*kaspersky\*'
      -'\*malware\*'
      -'\*sentinel\*'
      -'\*symantec\*'
      -'\*virus\*'

  condition:all of selection_*
Falsepositives:
  -False positives might occur due to the nature of the ScriptBlock being ingested as a big blob. Initial tuning is required.
  -As the "selection_cmdlet" is common in scripts the matching engine might slow down the search. Change into regex or a more accurate string to avoid heavy resource consumption if experienced
Level: medium