Title:
Non Interactive PowerShell Process Spawned
Status:
test
Description:Detects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.
References:
-https://web.archive.org/web/20200925032237/https://threathunterplaybook.com/notebooks/windows/02_execution/WIN-190410151110.html
Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements)
Date: 2019-09-12
modified:2025-02-28
Tags:
- -'attack.execution'
- -'attack.t1059.001'
Logsource:
- category: process_creation
- product: windows
Detection:
selection:
- Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- OriginalFileName:
- 'PowerShell.EXE'
- 'pwsh.dll'
filter_main_generic:
ParentImage|endswith:
-':\Windows\explorer.exe'
-':\Windows\System32\CompatTelRunner.exe'
-':\Windows\SysWOW64\explorer.exe'
filter_main_windows_update:
ParentImage:
':\$WINDOWS.~BT\Sources\SetupHost.exe'
filter_optional_vscode:
ParentImage|endswith:
'\AppData\Local\Programs\Microsoft VS Code\Code.exe'
ParentCommandLine|contains:
' --ms-enable-electron-run-as-node '
filter_optional_terminal:
ParentImage|contains:
':\Program Files\WindowsApps\Microsoft.WindowsTerminal_'
ParentImage|endswith:
'\WindowsTerminal.exe'
filter_optional_defender:
ParentImage|endswith:
':\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exe'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Likely. Many admin scripts and tools leverage PowerShell in their BAT or VB scripts which may trigger this rule often. It is best to add additional filters or use this to hunt for anomalies
Level:
low