Powershell Executed From Headless ConHost Process

 Original Source: [Sigma source]
Title: Powershell Executed From Headless ConHost Process
Status: test
Description:Detects the use of powershell commands from headless ConHost window. The "--headless" flag hides the windows from the user upon execution.
References:
  -https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software
Author: Matt Anderson (Huntress)
Date: 2024-07-23
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.001'
  • -'attack.t1059.003'
  • -'attack.t1564.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\conhost.exe' OriginalFileName:'CONHOST.EXE'   selection_cli:
    CommandLine|contains|all:
      -'--headless'
      -'powershell'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium