Title:
Windows PowerShell User Agent
Status:
test
Description:Detects Windows PowerShell Web Access
References:
-https://msdn.microsoft.com/powershell/reference/5.1/microsoft.powershell.utility/Invoke-WebRequest
Author: Florian Roth (Nextron Systems)
Date: 2017-03-13
modified:2021-11-27
Tags:
- -'attack.command-and-control'
- -'attack.t1071.001'
Logsource:
Detection:
selection:
c-useragent|contains:
' WindowsPowerShell/'
condition:
selection
Falsepositives:
-Administrative scripts that download files from the Internet
-Administrative scripts that retrieve certain website contents
Level:
medium