Malicious PowerShell Keywords

 Original Source: [Sigma source]
Title: Malicious PowerShell Keywords
Status: test
Description:Detects keywords from well-known PowerShell exploitation frameworks
References:
  -https://adsecurity.org/?p=2921
Author: Sean Metcalf (source), Florian Roth (Nextron Systems)
Date: 2017-03-05
modified:2023-06-20
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains:
      -'AdjustTokenPrivileges'
      -'IMAGE_NT_OPTIONAL_HDR64_MAGIC'
      -'Metasploit'
      -'Microsoft.Win32.UnsafeNativeMethods'
      -'Mimikatz'
      -'MiniDumpWriteDump'
      -'PAGE_EXECUTE_READ'
      -'ReadProcessMemory.Invoke'
      -'SE_PRIVILEGE_ENABLED'
      -'SECURITY_DELEGATION'
      -'TOKEN_ADJUST_PRIVILEGES'
      -'TOKEN_ALL_ACCESS'
      -'TOKEN_ASSIGN_PRIMARY'
      -'TOKEN_DUPLICATE'
      -'TOKEN_ELEVATION'
      -'TOKEN_IMPERSONATE'
      -'TOKEN_INFORMATION_CLASS'
      -'TOKEN_PRIVILEGES'
      -'TOKEN_QUERY'

  condition:selection
Falsepositives:
  -Depending on the scripts, this rule might require some initial tuning to fit the environment
Level: medium