Suspicious Start-Process PassThru

 Original Source: [Sigma source]
Title: Suspicious Start-Process PassThru
Status: test
Description:Powershell use PassThru option to start in background
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1036.003/T1036.003.md
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/start-process?view=powershell-7.6
Author: frack113
Date: 2022-01-15
modified:2026-05-18
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_cmdlet:
    ScriptBlockText|contains:
      -'Start-Process '
      -'saps '

  selection_param:
    ScriptBlockText|contains|all:
      -'-PassThru '
      -'-FilePath '

  condition:all of selection_*
Falsepositives:
  -Legitimate PowerShell scripts
Level: medium