Disable-WindowsOptionalFeature Command PowerShell

 Original Source: [Sigma source]
Title: Disable-WindowsOptionalFeature Command PowerShell
Status: test
Description:Detect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/5b67c9b141fa3918017f8fa44f2f88f0b1ecb9e1/atomics/T1562.001/T1562.001.md
  -https://learn.microsoft.com/en-us/powershell/module/dism/disable-windowsoptionalfeature?view=windowsserver2022-ps
Author: frack113
Date: 2022-09-10
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_cmd:
    ScriptBlockText|contains|all:
      -'Disable-WindowsOptionalFeature'
      -'-Online'
      -'-FeatureName'

  selection_feature:
    ScriptBlockText|contains:
      -'Windows-Defender-Gui'
      -'Windows-Defender-Features'
      -'Windows-Defender'
      -'Windows-Defender-ApplicationGuard'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: high