Gzip Archive Decode Via PowerShell

 Original Source: [Sigma source]
Title: Gzip Archive Decode Via PowerShell
Status: test
Description:Detects attempts of decoding encoded Gzip archives via PowerShell.
References:
  -https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution
Author: Hieu Tran
Date: 2023-03-13
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1132.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    CommandLine|contains|all:
      -'GZipStream'
      -'::Decompress'

  condition:selection
Falsepositives:
  -Legitimate administrative scripts may use this functionality. Use "ParentImage" in combination with the script names and allowed users and applications to filter legitimate executions
Level: medium