Suspicious XOR Encoded PowerShell Command

 Original Source: [Sigma source]
Title: Suspicious XOR Encoded PowerShell Command
Status: test
Description:Detects presence of a potentially xor encoded powershell command
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=65
  -https://redcanary.com/blog/yellow-cockatoo/
  -https://zero2auto.com/2020/05/19/netwalker-re/
  -https://mez0.cc/posts/cobaltstrike-powershell-exec/
Author: Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali
Date: 2018-09-05
modified:2023-01-30
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.001'
  • -'attack.t1140'
  • -'attack.t1027'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
Description:'Windows PowerShell' Product:'PowerShell Core 6'   selection_cli_xor:
    CommandLine|contains: 'bxor'
  selection_cli_other:
    CommandLine|contains:
      -'ForEach'
      -'for('
      -'for '
      -'-join '
      -'-join''
      -'-join"'
      -'-join`'
      -'::Join'
      -'[char]'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium