PowerShell Web Access Feature Enabled Via DISM

 Original Source: [Sigma source]
Title: PowerShell Web Access Feature Enabled Via DISM
Status: test
Description:Detects the use of DISM to enable the PowerShell Web Access feature, which could be used for remote access and potential abuse
References:
  -https://docs.microsoft.com/en-us/powershell/module/dism/enable-windowsoptionalfeature
  -https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
  -https://gist.github.com/MHaggis/7e67b659af9148fa593cf2402edebb41
Author: Michael Haag
Date: 2024-09-03
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1548.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\dism.exe' OriginalFileName:'DISM.EXE'   selection_cli:
    CommandLine|contains|all:
      -'WindowsPowerShellWebAccess'
      -'/online'
      -'/enable-feature'

  condition:all of selection_*
Falsepositives:
  -Legitimate PowerShell Web Access installations by administrators
Level: high