Powershell Suspicious Win32_PnPEntity

 Original Source: [Sigma source]
Title: Powershell Suspicious Win32_PnPEntity
Status: test
Description:Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1120/T1120.md
Author: frack113
Date: 2021-08-23
modified:2022-12-25
Tags:
  • -'attack.discovery'
  • -'attack.t1120'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains: 'Win32_PnPEntity'
  condition:selection
Falsepositives:
  -Admin script
Level: low