HackTool - Empire PowerShell Launch Parameters

 Original Source: [Sigma source]
Title: HackTool - Empire PowerShell Launch Parameters
Status: test
Description:Detects suspicious powershell command line parameters used in Empire
References:
  -https://github.com/EmpireProject/Empire/blob/c2ba61ca8d2031dad0cfc1d5770ba723e8b710db/lib/common/helpers.py#L165
  -https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/deaduser.py#L191
  -https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/resolver.py#L178
  -https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
Author: Florian Roth (Nextron Systems)
Date: 2019-04-20
modified:2023-02-21
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -' -NoP -sta -NonI -W Hidden -Enc '
      -' -noP -sta -w 1 -enc '
      -' -NoP -NonI -W Hidden -enc '
      -' -noP -sta -w 1 -enc'
      -' -enc SQB'
      -' -nop -exec bypass -EncodedCommand '

  condition:selection
Falsepositives:
  -Other tools that incidentally use the same command line parameters
Level: high