ConvertTo-SecureString Cmdlet Usage Via CommandLine

 Original Source: [Sigma source]
Title: ConvertTo-SecureString Cmdlet Usage Via CommandLine
Status: test
Description:Detects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=65
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/convertto-securestring?view=powershell-7.3#examples
Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton
Date: 2020-10-11
modified:2023-02-01
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains: 'ConvertTo-SecureString'
  condition:all of selection_*
Falsepositives:
  -Legitimate use to pass password to different powershell commands
Level: medium