Suspicious PowerShell Invocation From Script Engines

 Original Source: [Sigma source]
Title: Suspicious PowerShell Invocation From Script Engines
Status: test
Description:Detects suspicious powershell invocations from interpreters or unusual programs
References:
  -https://www.securitynewspaper.com/2017/03/20/attackers-leverage-excel-powershell-dns-latest-non-malware-attack/
Author: Florian Roth (Nextron Systems)
Date: 2019-01-16
modified:2023-01-05
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\wscript.exe'
      -'\cscript.exe'

    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

  filter_health_service:
    CurrentDirectory|contains: '\Health Service State\'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Microsoft Operations Manager (MOM)
  -Other scripts
Level: medium