Potential PowerShell Obfuscation Using Character Join

 Original Source: [Sigma source]
Title: Potential PowerShell Obfuscation Using Character Join
Status: test
Description:Detects specific techniques often seen used inside of PowerShell scripts to obfscuate Alias creation
References:
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-09
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'-Alias'
      -' -Value (-join('

  condition:selection
Falsepositives:
  -Unknown
Level: low