This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Powershell Script Execution From Temp Folder
Original Source:
[Sigma source]
Title:
Potentially Suspicious Powershell Script Execution From Temp Folder
Status:
test
Description:
Detects a potentially suspicious powershell script executions from temporary folder
References:
-https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
Author:
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton
Date:
2021-07-14
modified:
2026-02-17
Tags:
-'attack.execution'
-'attack.t1059.001'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
-'\powershell.exe'
-'\pwsh.exe'
CommandLine|contains
:
-'\Windows\Temp'
-'\Temporary Internet'
-'\AppData\Local\Temp'
-'\AppData\Roaming\Temp'
-'%TEMP%'
-'%TMP%'
-'%LocalAppData%\Temp'
filter_optional_vscode:
CommandLine|contains
:
'-WindowStyle hidden -Verb runAs'
filter_optional_amazon_ec2:
CommandLine|contains
:
'\Windows\system32\config\systemprofile\AppData\Local\Temp\Amazon\EC2-Windows\'
filter_optional_generic:
CommandLine|contains
:
-' >'
-'Out-File'
-'ConvertTo-Json'
filter_optional_chocolatey_installer:
ParentImage
:
-'C:\Windows\System32\Msiexec.exe'
-'C:\Windows\SysWOW64\Msiexec.exe'
Image|endswith
:
'\powershell.exe'
CommandLine|contains|all
:
-'-NoProfile -ExecutionPolicy Bypass -Command'
-'AppData\Local\Temp\'
-'Install-Chocolatey.ps1'
condition
:
selection and not 1 of filter_optional_*
Falsepositives:
-Administrative scripts
Level:
medium