HackTool - CrackMapExec PowerShell Obfuscation

 Original Source: [Sigma source]
Title: HackTool - CrackMapExec PowerShell Obfuscation
Status: test
Description:The CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.
References:
  -https://github.com/byt3bl33d3r/CrackMapExec
  -https://github.com/byt3bl33d3r/CrackMapExec/blob/0a49f75347b625e81ee6aa8c33d3970b5515ea9e/cme/helpers/powershell.py#L242
Author: Thomas Patzke
Date: 2020-05-22
modified:2023-02-21
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.001'
  • -'attack.t1027.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains:
      -'join*split'
      -'( $ShellId[1]+$ShellId[13]+'x')'
      -'( $PSHome[*]+$PSHOME[*]+'
      -'( $env:Public[13]+$env:Public[5]+'x')'
      -'( $env:ComSpec[4,*,25]-Join'')'
      -'[1,3]+'x'-Join'')'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high