This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential WinAPI Calls Via PowerShell Scripts
Original Source:
[Sigma source]
Title:
Potential WinAPI Calls Via PowerShell Scripts
Status:
test
Description:
Detects usage of WinAPI functions in PowerShell scripts. It may indicate attempts to perform actions such as process injection, token stealing, or other malicious activities that leverage Windows API calls. These techniques are commonly used to evade traditional file-based detections by loading and executing code directly in memory.
References:
-https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
-https://github.com/PowerShellMafia/PowerSploit/blob/1980f403ee78234eae4d93b50890d02f827a099f/CodeExecution/Invoke-Shellcode.ps1
-https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
Author:
Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community
Date:
2020-10-06
modified:
2026-04-29
Tags:
-'attack.execution'
-'attack.t1059.001'
-'attack.t1106'
-'attack.stealth'
-'attack.t1620'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection_injection:
ScriptBlockText|contains|all
:
-'VirtualAlloc'
-'OpenProcess'
-'WriteProcessMemory'
-'CreateRemoteThread'
selection_token_steal:
ScriptBlockText|contains|all
:
-'OpenProcessToken'
-'LookupPrivilegeValue'
-'AdjustTokenPrivileges'
selection_duplicate_token:
ScriptBlockText|contains|all
:
-'OpenProcessToken'
-'DuplicateTokenEx'
-'CloseHandle'
selection_process_write_read:
ScriptBlockText|contains|all
:
-'WriteProcessMemory'
-'VirtualAlloc'
-'ReadProcessMemory'
-'VirtualFree'
selection_local_shellcode_injection:
ScriptBlockText|contains|all
:
-'VirtualAlloc'
-'GetDelegateForFunctionPointer'
-'Marshal.Copy'
condition
:
1 of selection_*
Falsepositives:
-Unknown
Level:
high