Title:
Malicious PowerShell Keywords
Status:
test
Description:Detects keywords from well-known PowerShell exploitation frameworks
References:
-https://adsecurity.org/?p=2921
Author: Sean Metcalf (source), Florian Roth (Nextron Systems)
Date: 2017-03-05
modified:2023-06-20
Tags:
- -'attack.execution'
- -'attack.t1059.001'
Logsource:
- product: windows
- category: ps_script
- definition: Requirements: Script Block Logging must be enabled
Detection:
selection:
ScriptBlockText|contains:
-'AdjustTokenPrivileges'
-'IMAGE_NT_OPTIONAL_HDR64_MAGIC'
-'Metasploit'
-'Microsoft.Win32.UnsafeNativeMethods'
-'Mimikatz'
-'MiniDumpWriteDump'
-'PAGE_EXECUTE_READ'
-'ReadProcessMemory.Invoke'
-'SE_PRIVILEGE_ENABLED'
-'SECURITY_DELEGATION'
-'TOKEN_ADJUST_PRIVILEGES'
-'TOKEN_ALL_ACCESS'
-'TOKEN_ASSIGN_PRIMARY'
-'TOKEN_DUPLICATE'
-'TOKEN_ELEVATION'
-'TOKEN_IMPERSONATE'
-'TOKEN_INFORMATION_CLASS'
-'TOKEN_PRIVILEGES'
-'TOKEN_QUERY'
condition:
selection
Falsepositives:
-Depending on the scripts, this rule might require some initial tuning to fit the environment
Level:
medium