PowerShell Download Pattern

 Original Source: [Sigma source]
Title: PowerShell Download Pattern
Status: test
Description:Detects a Powershell process that contains download commands in its command line string
References:
  -https://blog.redteam.pl/2020/06/black-kingdom-ransomware.html
  -https://lab52.io/blog/winter-vivern-all-summer/
  -https://hatching.io/blog/powershell-analysis/
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
Date: 2019-01-16
modified:2025-10-20
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell_ise.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell_ISE.EXE'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains|all:
      -'new-object'
      -'net.webclient).'
      -'download'

    CommandLine|contains:
      -'string('
      -'file('

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium