This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Malicious Nishang PowerShell Commandlets
Original Source:
[Sigma source]
Title:
Malicious Nishang PowerShell Commandlets
Status:
test
Description:
Detects Commandlet names and arguments from the Nishang exploitation framework
References:
-https://github.com/samratashok/nishang
Author:
Alec Costello
Date:
2019-05-16
modified:
2023-01-16
Tags:
-'attack.execution'
-'attack.t1059.001'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection:
ScriptBlockText|contains
:
-'Add-ConstrainedDelegationBackdoor'
-'Copy-VSS'
-'Create-MultipleSessions'
-'DataToEncode'
-'DNS_TXT_Pwnage'
-'Do-Exfiltration-Dns'
-'Download_Execute'
-'Download-Execute-PS'
-'DownloadAndExtractFromRemoteRegistry'
-'DumpCerts'
-'DumpCreds'
-'DumpHashes'
-'Enable-DuplicateToken'
-'Enable-Duplication'
-'Execute-Command-MSSQL'
-'Execute-DNSTXT-Code'
-'Execute-OnTime'
-'ExetoText'
-'exfill'
-'ExfilOption'
-'FakeDC'
-'FireBuster'
-'FireListener'
-'Get-Information '
-'Get-PassHints'
-'Get-Web-Credentials'
-'Get-WebCredentials'
-'Get-WLAN-Keys'
-'HTTP-Backdoor'
-'Invoke-AmsiBypass'
-'Invoke-BruteForce'
-'Invoke-CredentialsPhish'
-'Invoke-Decode'
-'Invoke-Encode'
-'Invoke-Interceptor'
-'Invoke-JSRatRegsvr'
-'Invoke-JSRatRundll'
-'Invoke-MimikatzWDigestDowngrade'
-'Invoke-NetworkRelay'
-'Invoke-PowerShellIcmp'
-'Invoke-PowerShellUdp'
-'Invoke-Prasadhak'
-'Invoke-PSGcat'
-'Invoke-PsGcatAgent'
-'Invoke-SessionGopher'
-'Invoke-SSIDExfil'
-'LoggedKeys'
-'Nishang'
-'NotAllNameSpaces'
-'Out-CHM'
-'OUT-DNSTXT'
-'Out-HTA'
-'Out-RundllCommand'
-'Out-SCF'
-'Out-SCT'
-'Out-Shortcut'
-'Out-WebQuery'
-'Out-Word'
-'Parse_Keys'
-'Password-List'
-'Powerpreter'
-'Remove-Persistence'
-'Remove-PoshRat'
-'Remove-Update'
-'Run-EXEonRemote'
-'Set-DCShadowPermissions'
-'Set-RemotePSRemoting'
-'Set-RemoteWMI'
-'Shellcode32'
-'Shellcode64'
-'StringtoBase64'
-'TexttoExe'
condition
:
selection
Falsepositives:
-Unknown
Level:
high