This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Empire PowerShell Launch Parameters
Original Source:
[Sigma source]
Title:
HackTool - Empire PowerShell Launch Parameters
Status:
test
Description:
Detects suspicious powershell command line parameters used in Empire
References:
-https://github.com/EmpireProject/Empire/blob/c2ba61ca8d2031dad0cfc1d5770ba723e8b710db/lib/common/helpers.py#L165
-https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/deaduser.py#L191
-https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/resolver.py#L178
-https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
Author:
Florian Roth (Nextron Systems)
Date:
2019-04-20
modified:
2023-02-21
Tags:
-'attack.execution'
-'attack.t1059.001'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-' -NoP -sta -NonI -W Hidden -Enc '
-' -noP -sta -w 1 -enc '
-' -NoP -NonI -W Hidden -enc '
-' -noP -sta -w 1 -enc'
-' -enc SQB'
-' -nop -exec bypass -EncodedCommand '
condition
:
selection
Falsepositives:
-Other tools that incidentally use the same command line parameters
Level:
high