Suspicious TCP Tunnel Via PowerShell Script

 Original Source: [Sigma source]
Title: Suspicious TCP Tunnel Via PowerShell Script
Status: test
Description:Detects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity
References:
  -https://github.com/Arno0x/PowerShellScripts/blob/a6b7d5490fbf0b20f91195838f3a11156724b4f7/proxyTunnel.ps1
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-08
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1090'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'[System.Net.HttpWebRequest]'
      -'System.Net.Sockets.TcpListener'
      -'AcceptTcpClient'

  condition:selection
Falsepositives:
  -Unknown
Level: medium