PowerShell

T1059.001

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

PowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.

A number of PowerShell-based offensive testing tools are available, including Empire, PowerSploit, PoshC2, and PSAttack.

PowerShell commands/scripts can also be executed without directly invoking the powershell.exe binary through interfaces to PowerShell's underlying System.Management.Automation assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).

Detection rules256

Rules on DetectionCode tagged with T1059.001.

Sigma183

RuleLevelLog source
Bad Opsec Powershell Code Artifactscriticalwindows / ps_module
Silence.EDA Detectioncriticalwindows / ps_script
AWS EC2 Startup Shell Script Changehighaws / NULL
Base64 Encoded PowerShell Command Detectedhighwindows / process_creation
BloodHound Collection Fileshighwindows / file_event
Cmd.EXE Missing Space Characters Execution Anomalyhighwindows / process_creation
DSInternals Suspicious PowerShell Cmdletshighwindows / process_creation
DSInternals Suspicious PowerShell Cmdlets - ScriptBlockhighwindows / ps_script
Exchange PowerShell Snap-Ins Usagehighwindows / process_creation
Execution of Powershell Script in Public Folderhighwindows / process_creation
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creation
HackTool - Covenant PowerShell Launcherhighwindows / process_creation
HackTool - CrackMapExec Executionhighwindows / process_creation
HackTool - CrackMapExec Execution Patternshighwindows / process_creation
HackTool - CrackMapExec PowerShell Obfuscationhighwindows / process_creation

Splunk73

RuleTypeRiskData source
Any Powershell DownloadFileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Any Powershell DownloadStringTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
CrushFTP Authentication Bypass ExploitationTTPNULLCrushFTP
Detect Certify With PowerShell Script Block LoggingTTPNULLPowershell Script Block Logging 4104
Detect Empire with PowerShell Script Block LoggingTTPNULLPowershell Script Block Logging 4104
Detect Mimikatz With PowerShell Script Block LoggingTTPNULLPowershell Script Block Logging 4104
Exchange PowerShell Module UsageTTPNULLPowershell Script Block Logging 4104
First time seen command line argumentHuntingNULLSysmon EventID 1
Get-ForestTrust with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
GetLocalUser with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
GetWmiObject User Account with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Malicious PowerShell Process - Execution Policy BypassAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Malicious PowerShell Process With Obfuscation TechniquesTTPNULLSysmon EventID 1

Groups85

Show 61 more

Software131

Show 107 more

Campaigns17

Procedure examples233

Groups85

Used byProcedure example
GroupAkira

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

GroupAPT19

APT19 used PowerShell commands to execute payloads.

GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

GroupAPT3

APT3 has used PowerShell on victim systems to download and run payloads after exploitation.

GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

GroupAPT33

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

View all 85 groups examples

Software131

Used byProcedure example
ToolAADInternals

AADInternals is written and executed via PowerShell.

MalwareAkira

Akira will execute PowerShell commands to delete system volume shadow copies.

MalwareAppleSeed

AppleSeed has the ability to execute its payload via PowerShell.

MalwareAutoIt backdoor

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

MalwareBADHATCH

BADHATCH can utilize `powershell.exe` to execute commands on a compromised host.

MalwareBandook

Bandook has used PowerShell loaders as part of execution.

MalwareBazar

Bazar can execute a PowerShell script received from C2.

MalwareBlack Basta

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

View all 131 software examples

Campaigns17

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet Get-ChildItem to access credentials, among other PowerShell functions deployed.

CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

CampaignC0032

During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping.

CampaignFrankenstein

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

View all 17 campaigns examples

References5

  1. Github PSAttack Open source
    Haight, J. (2016, April 21). PS>Attack. Retrieved September 27, 2024.
  2. Microsoft PSfromCsharp APR 2014 Open source
    Babinec, K. (2014, April 28). Executing PowerShell scripts from C#. Retrieved April 22, 2019.
  3. SilentBreak Offensive PS Dec 2015 Open source
    Christensen, L.. (2015, December 28). The Evolution of Offensive PowerShell Invocation. Retrieved December 8, 2018.
  4. Sixdub PowerPick Jan 2016 Open source
    Warner, J.. (2015, January 6). Inexorable PowerShell – A Red Teamer’s Tale of Overcoming Simple AppLocker Policies. Retrieved December 8, 2018.
  5. TechNet PowerShell Open source
    Microsoft. (n.d.). Windows PowerShell Scripting. Retrieved April 28, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.