Malicious ShellIntel PowerShell Commandlets

 Original Source: [Sigma source]
Title: Malicious ShellIntel PowerShell Commandlets
Status: test
Description:Detects Commandlet names from ShellIntel exploitation scripts.
References:
  -https://github.com/Shellntel/scripts/
Author: Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)
Date: 2021-08-09
modified:2023-01-02
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains:
      -'Invoke-SMBAutoBrute'
      -'Invoke-GPOLinks'
      -'Invoke-Potato'

  condition:selection
Falsepositives:
  -Unknown
Level: high