Renamed Powershell Under Powershell Channel

 Original Source: [Sigma source]
Title: Renamed Powershell Under Powershell Channel
Status: test
Description:Detects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
Author: Harish Segar, frack113
Date: 2020-06-29
modified:2025-01-20
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.001'
  • -'attack.t1036.003'
Logsource:
  • product: windows
  • category: ps_classic_start
Detection:
  selection:
    Data|contains: 'HostName=ConsoleHost'
  filter_main_ps:
    Data|contains:
      -'HostApplication=powershell'
      -'HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell'
      -'HostApplication=C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell'
      -'HostApplication=C:/Windows/System32/WindowsPowerShell/v1.0/powershell'
      -'HostApplication=C:/Windows/SysWOW64/WindowsPowerShell/v1.0/powershell'
      -'HostApplication=C:\\\\WINDOWS\\\\system32\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe'
      -'HostApplication=C:\\\\WINDOWS\\\\SysWOW64\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe'

  filter_main_host_application_null:
    Data|re: 'HostId=[a-zA-Z0-9-]{36}\s+EngineVersion='
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: low