Malicious Nishang PowerShell Commandlets

 Original Source: [Sigma source]
Title: Malicious Nishang PowerShell Commandlets
Status: test
Description:Detects Commandlet names and arguments from the Nishang exploitation framework
References:
  -https://github.com/samratashok/nishang
Author: Alec Costello
Date: 2019-05-16
modified:2023-01-16
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains:
      -'Add-ConstrainedDelegationBackdoor'
      -'Copy-VSS'
      -'Create-MultipleSessions'
      -'DataToEncode'
      -'DNS_TXT_Pwnage'
      -'Do-Exfiltration-Dns'
      -'Download_Execute'
      -'Download-Execute-PS'
      -'DownloadAndExtractFromRemoteRegistry'
      -'DumpCerts'
      -'DumpCreds'
      -'DumpHashes'
      -'Enable-DuplicateToken'
      -'Enable-Duplication'
      -'Execute-Command-MSSQL'
      -'Execute-DNSTXT-Code'
      -'Execute-OnTime'
      -'ExetoText'
      -'exfill'
      -'ExfilOption'
      -'FakeDC'
      -'FireBuster'
      -'FireListener'
      -'Get-Information '
      -'Get-PassHints'
      -'Get-Web-Credentials'
      -'Get-WebCredentials'
      -'Get-WLAN-Keys'
      -'HTTP-Backdoor'
      -'Invoke-AmsiBypass'
      -'Invoke-BruteForce'
      -'Invoke-CredentialsPhish'
      -'Invoke-Decode'
      -'Invoke-Encode'
      -'Invoke-Interceptor'
      -'Invoke-JSRatRegsvr'
      -'Invoke-JSRatRundll'
      -'Invoke-MimikatzWDigestDowngrade'
      -'Invoke-NetworkRelay'
      -'Invoke-PowerShellIcmp'
      -'Invoke-PowerShellUdp'
      -'Invoke-Prasadhak'
      -'Invoke-PSGcat'
      -'Invoke-PsGcatAgent'
      -'Invoke-SessionGopher'
      -'Invoke-SSIDExfil'
      -'LoggedKeys'
      -'Nishang'
      -'NotAllNameSpaces'
      -'Out-CHM'
      -'OUT-DNSTXT'
      -'Out-HTA'
      -'Out-RundllCommand'
      -'Out-SCF'
      -'Out-SCT'
      -'Out-Shortcut'
      -'Out-WebQuery'
      -'Out-Word'
      -'Parse_Keys'
      -'Password-List'
      -'Powerpreter'
      -'Remove-Persistence'
      -'Remove-PoshRat'
      -'Remove-Update'
      -'Run-EXEonRemote'
      -'Set-DCShadowPermissions'
      -'Set-RemotePSRemoting'
      -'Set-RemoteWMI'
      -'Shellcode32'
      -'Shellcode64'
      -'StringtoBase64'
      -'TexttoExe'

  condition:selection
Falsepositives:
  -Unknown
Level: high