Potential WinAPI Calls Via PowerShell Scripts

 Original Source: [Sigma source]
Title: Potential WinAPI Calls Via PowerShell Scripts
Status: test
Description:Detects usage of WinAPI functions in PowerShell scripts. It may indicate attempts to perform actions such as process injection, token stealing, or other malicious activities that leverage Windows API calls. These techniques are commonly used to evade traditional file-based detections by loading and executing code directly in memory.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
  -https://github.com/PowerShellMafia/PowerSploit/blob/1980f403ee78234eae4d93b50890d02f827a099f/CodeExecution/Invoke-Shellcode.ps1
  -https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
Author: Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community
Date: 2020-10-06
modified:2026-04-29
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
  • -'attack.t1106'
  • -'attack.stealth'
  • -'attack.t1620'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_injection:
    ScriptBlockText|contains|all:
      -'VirtualAlloc'
      -'OpenProcess'
      -'WriteProcessMemory'
      -'CreateRemoteThread'

  selection_token_steal:
    ScriptBlockText|contains|all:
      -'OpenProcessToken'
      -'LookupPrivilegeValue'
      -'AdjustTokenPrivileges'

  selection_duplicate_token:
    ScriptBlockText|contains|all:
      -'OpenProcessToken'
      -'DuplicateTokenEx'
      -'CloseHandle'

  selection_process_write_read:
    ScriptBlockText|contains|all:
      -'WriteProcessMemory'
      -'VirtualAlloc'
      -'ReadProcessMemory'
      -'VirtualFree'

  selection_local_shellcode_injection:
    ScriptBlockText|contains|all:
      -'VirtualAlloc'
      -'GetDelegateForFunctionPointer'
      -'Marshal.Copy'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high