PowerShell Script Run in AppData

 Original Source: [Sigma source]
Title: PowerShell Script Run in AppData
Status: test
Description:Detects a suspicious command line execution that invokes PowerShell with reference to an AppData folder
References:
  -https://twitter.com/JohnLaTwC/status/1082851155481288706
  -https://app.any.run/tasks/f87f1c4e-47e2-4c46-9cf4-31454c06ce03
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Date: 2019-01-09
modified:2022-07-14
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    CommandLine|contains:
      -'powershell.exe'
      -'\powershell'
      -'\pwsh'
      -'pwsh.exe'

  selection2:
    CommandLine|contains|all:
      -'/c '
      -'\AppData\'

    CommandLine|contains:
      -'Local\'
      -'Roaming\'

  condition:all of selection*
Falsepositives:
  -Administrative scripts
Level: medium