Title:Suspicious FromBase64String Usage On Gzip Archive - Ps Script Status:test Description:Detects attempts of decoding a base64 Gzip archive in a PowerShell script. This technique is often used as a method to load malicious content into memory afterward. References: -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=43 Author: frack113 Date: 2022-12-23 modified:None Tags:
-'attack.command-and-control'
-'attack.t1132.001'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled