Powershell Directory Enumeration

 Original Source: [Sigma source]
Title: Powershell Directory Enumeration
Status: test
Description:Detects technique used by MAZE ransomware to enumerate directories using Powershell
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1083/T1083.md
  -https://www.mandiant.com/resources/tactics-techniques-procedures-associated-with-maze-ransomware-incidents
Author: frack113
Date: 2022-03-17
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1083'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'foreach'
      -'Get-ChildItem'
      -'-Path '
      -'-ErrorAction '
      -'SilentlyContinue'
      -'Out-File '
      -'-append'

  condition:selection
Falsepositives:
  -Legitimate PowerShell scripts
Level: medium