This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Audio Capture via PowerShell
Original Source:
[Sigma source]
Title:
Audio Capture via PowerShell
Status:
test
Description:
Detects audio capture via PowerShell Cmdlet.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
-https://eqllib.readthedocs.io/en/latest/analytics/ab7a6ef4-0983-4275-a4f1-5c6bd3c31c23.html
-https://github.com/frgnca/AudioDeviceCmdlets
Author:
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date:
2019-10-24
modified:
2023-04-06
Tags:
-'attack.collection'
-'attack.t1123'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-'WindowsAudioDevice-Powershell-Cmdlet'
-'Toggle-AudioDevice'
-'Get-AudioDevice '
-'Set-AudioDevice '
-'Write-AudioDevice '
condition
:
selection
Falsepositives:
-Legitimate audio capture by legitimate user.
Level:
medium