Potential PowerShell Command Line Obfuscation

 Original Source: [Sigma source]
Title: Potential PowerShell Command Line Obfuscation
Status: test
Description:Detects the PowerShell command lines with special characters
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=64
Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp)
Date: 2020-10-15
modified:2024-04-15
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_re:
CommandLine|re:'\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+' CommandLine|re:'\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{' CommandLine|re:'\^.*\^.*\^.*\^.*\^' CommandLine|re:'`.*`.*`.*`.*`'   filter_optional_amazonSSM:
    ParentImage: 'C:\Program Files\Amazon\SSM\ssm-document-worker.exe'
  filter_optional_defender_atp:
    CommandLine|contains:
      -'new EventSource("Microsoft.Windows.Sense.Client.Management"'
      -'public static extern bool InstallELAMCertificateInfo(SafeFileHandle handle);'

  condition:all of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Amazon SSM Document Worker
  -Windows Defender ATP
Level: high