Malicious PowerShell Commandlets - PoshModule

 Original Source: [Sigma source]
Title: Malicious PowerShell Commandlets - PoshModule
Status: test
Description:Detects Commandlet names from well-known PowerShell exploitation frameworks
References:
  -https://adsecurity.org/?p=2921
  -https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries
  -https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1
  -https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1
  -https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1
  -https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1
  -https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/
  -https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/
  -https://github.com/calebstewart/CVE-2021-1675
  -https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1
  -https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html
  -https://github.com/HarmJ0y/DAMP
  -https://github.com/samratashok/nishang
  -https://github.com/DarkCoderSc/PowerRunAsSystem/
  -https://github.com/besimorhino/powercat
  -https://github.com/Kevin-Robertson/Powermad
  -https://github.com/adrecon/ADRecon
  -https://github.com/adrecon/AzureADRecon
  -https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1
  -https://github.com/The-Viper-One/Invoke-PowerDPAPI/
  -https://github.com/Arno0x/DNSExfiltrator/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-20
modified:2025-12-10
Tags:
  • -'attack.execution'
  • -'attack.discovery'
  • -'attack.t1482'
  • -'attack.t1087'
  • -'attack.t1087.001'
  • -'attack.t1087.002'
  • -'attack.t1069.001'
  • -'attack.t1069.002'
  • -'attack.t1069'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_module
  • definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
Detection:
  selection:
    Payload|contains:
      -'Add-Exfiltration'
      -'Add-Persistence'
      -'Add-RegBackdoor'
      -'Add-RemoteRegBackdoor'
      -'Add-ScrnSaveBackdoor'
      -'BadSuccessor'
      -'Check-VM'
      -'ConvertTo-Rc4ByteStream'
      -'Decrypt-Hash'
      -'Disable-ADIDNSNode'
      -'Disable-MachineAccount'
      -'Do-Exfiltration'
      -'Enable-ADIDNSNode'
      -'Enable-MachineAccount'
      -'Enabled-DuplicateToken'
      -'Exploit-Jboss'
      -'Export-ADR'
      -'Export-ADRCSV'
      -'Export-ADRExcel'
      -'Export-ADRHTML'
      -'Export-ADRJSON'
      -'Export-ADRXML'
      -'Find-Fruit'
      -'Find-GPOLocation'
      -'Find-TrustedDocuments'
      -'Get-ADIDNS'
      -'Get-ApplicationHost'
      -'Get-ChromeDump'
      -'Get-ClipboardContents'
      -'Get-FoxDump'
      -'Get-GPPPassword'
      -'Get-IndexedItem'
      -'Get-KerberosAESKey'
      -'Get-Keystrokes'
      -'Get-LSASecret'
      -'Get-MachineAccountAttribute'
      -'Get-MachineAccountCreator'
      -'Get-PassHashes'
      -'Get-RegAlwaysInstallElevated'
      -'Get-RegAutoLogon'
      -'Get-RemoteBootKey'
      -'Get-RemoteCachedCredential'
      -'Get-RemoteLocalAccountHash'
      -'Get-RemoteLSAKey'
      -'Get-RemoteMachineAccountHash'
      -'Get-RemoteNLKMKey'
      -'Get-RickAstley'
      -'Get-Screenshot'
      -'Get-SecurityPackages'
      -'Get-ServiceFilePermission'
      -'Get-ServicePermission'
      -'Get-ServiceUnquoted'
      -'Get-SiteListPassword'
      -'Get-System'
      -'Get-TimedScreenshot'
      -'Get-UnattendedInstallFile'
      -'Get-Unconstrained'
      -'Get-USBKeystrokes'
      -'Get-VaultCredential'
      -'Get-VulnAutoRun'
      -'Get-VulnSchTask'
      -'Grant-ADIDNSPermission'
      -'Gupt-Backdoor'
      -'HTTP-Login'
      -'Install-ServiceBinary'
      -'Install-SSP'
      -'Invoke-ACLScanner'
      -'Invoke-ADRecon'
      -'Invoke-ADSBackdoor'
      -'Invoke-AgentSmith'
      -'Invoke-AllChecks'
      -'Invoke-ARPScan'
      -'Invoke-AzureHound'
      -'Invoke-BackdoorLNK'
      -'Invoke-BadPotato'
      -'Invoke-BetterSafetyKatz'
      -'Invoke-BypassUAC'
      -'Invoke-Carbuncle'
      -'Invoke-Certify'
      -'Invoke-ConPtyShell'
      -'Invoke-CredentialInjection'
      -'Invoke-DAFT'
      -'Invoke-DCSync'
      -'Invoke-DinvokeKatz'
      -'Invoke-DllInjection'
      -'Invoke-DNSUpdate'
      -'Invoke-DNSExfiltrator'
      -'Invoke-DomainPasswordSpray'
      -'Invoke-DowngradeAccount'
      -'Invoke-EgressCheck'
      -'Invoke-Eyewitness'
      -'Invoke-FakeLogonScreen'
      -'Invoke-Farmer'
      -'Invoke-Get-RBCD-Threaded'
      -'Invoke-Gopher'
      -'Invoke-Grouper'
      -'Invoke-HandleKatz'
      -'Invoke-ImpersonatedProcess'
      -'Invoke-ImpersonateSystem'
      -'Invoke-InteractiveSystemPowerShell'
      -'Invoke-Internalmonologue'
      -'Invoke-Inveigh'
      -'Invoke-InveighRelay'
      -'Invoke-KrbRelay'
      -'Invoke-LdapSignCheck'
      -'Invoke-Lockless'
      -'Invoke-MalSCCM'
      -'Invoke-Mimikatz'
      -'Invoke-Mimikittenz'
      -'Invoke-MITM6'
      -'Invoke-NanoDump'
      -'Invoke-NetRipper'
      -'Invoke-Nightmare'
      -'Invoke-NinjaCopy'
      -'Invoke-OfficeScrape'
      -'Invoke-OxidResolver'
      -'Invoke-P0wnedshell'
      -'Invoke-Paranoia'
      -'Invoke-PortScan'
      -'Invoke-PoshRatHttp'
      -'Invoke-PostExfil'
      -'Invoke-PowerDump'
      -'Invoke-PowerDPAPI'
      -'Invoke-PowerShellTCP'
      -'Invoke-PowerShellWMI'
      -'Invoke-PPLDump'
      -'Invoke-PsExec'
      -'Invoke-PSInject'
      -'Invoke-PsUaCme'
      -'Invoke-ReflectivePEInjection'
      -'Invoke-ReverseDNSLookup'
      -'Invoke-Rubeus'
      -'Invoke-RunAs'
      -'Invoke-SafetyKatz'
      -'Invoke-SauronEye'
      -'Invoke-SCShell'
      -'Invoke-Seatbelt'
      -'Invoke-ServiceAbuse'
      -'Invoke-ShadowSpray'
      -'Invoke-Sharp'
      -'Invoke-Shellcode'
      -'Invoke-SMBScanner'
      -'Invoke-Snaffler'
      -'Invoke-Spoolsample'
      -'Invoke-SpraySinglePassword'
      -'Invoke-SSHCommand'
      -'Invoke-StandIn'
      -'Invoke-StickyNotesExtract'
      -'Invoke-SystemCommand'
      -'Invoke-Tasksbackdoor'
      -'Invoke-Tater'
      -'Invoke-Thunderfox'
      -'Invoke-ThunderStruck'
      -'Invoke-TokenManipulation'
      -'Invoke-Tokenvator'
      -'Invoke-TotalExec'
      -'Invoke-UrbanBishop'
      -'Invoke-UserHunter'
      -'Invoke-VoiceTroll'
      -'Invoke-Whisker'
      -'Invoke-WinEnum'
      -'Invoke-winPEAS'
      -'Invoke-WireTap'
      -'Invoke-WmiCommand'
      -'Invoke-WMIExec'
      -'Invoke-WScriptBypassUAC'
      -'Invoke-Zerologon'
      -'MailRaider'
      -'New-ADIDNSNode'
      -'New-DNSRecordArray'
      -'New-HoneyHash'
      -'New-InMemoryModule'
      -'New-MachineAccount'
      -'New-SOASerialNumberArray'
      -'Out-Minidump'
      -'Port-Scan'
      -'PowerBreach'
      -'powercat '
      -'PowerUp'
      -'PowerView'
      -'Remove-ADIDNSNode'
      -'Remove-MachineAccount'
      -'Remove-Update'
      -'Rename-ADIDNSNode'
      -'Revoke-ADIDNSPermission'
      -'Set-ADIDNSNode'
      -'Set-MacAttribute'
      -'Set-MachineAccountAttribute'
      -'Set-Wallpaper'
      -'Show-TargetScreen'
      -'Start-CaptureServer'
      -'Start-Dnscat2'
      -'Start-WebcamRecorder'
      -'Veeam-Get-Creds'
      -'VolumeShadowCopyTools'

  condition:selection
Falsepositives:
  -Unknown
Level: high