PowerShell Base64 Encoded FromBase64String Cmdlet

 Original Source: [Sigma source]
Title: PowerShell Base64 Encoded FromBase64String Cmdlet
Status: test
Description:Detects usage of a base64 encoded "FromBase64String" cmdlet in a process command line
References:
  -Internal Research
Author: Florian Roth (Nextron Systems)
Date: 2019-08-24
modified:2023-04-06
Tags:
  • -'attack.stealth'
  • -'attack.t1140'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
CommandLine|base64offset|contains:'::FromBase64String'     - CommandLine|contains:
      - 'OgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcA'
      - 'oAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnA'
      - '6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZw'
  condition:selection
Falsepositives:
  -Unknown
Level: high