Suspicious Execution of Powershell with Base64

 Original Source: [Sigma source]
Title: Suspicious Execution of Powershell with Base64
Status: test
Description:Commandline to launch powershell with a base64 payload
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1059.001/T1059.001.md#atomic-test-20---powershell-invoke-known-malicious-cmdlets
  -https://unit42.paloaltonetworks.com/unit42-pulling-back-the-curtains-on-encodedcommand-powershell-attacks/
  -https://mikefrobbins.com/2017/06/15/simple-obfuscation-with-powershell-using-base64-encoding/
Author: frack113
Date: 2022-01-02
modified:2023-01-05
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains:
      -' -e '
      -' -en '
      -' -enc '
      -' -enco'
      -' -ec '

  filter_encoding:
    CommandLine|contains: ' -Encoding '
  filter_azure:
    ParentImage|contains:
      -'C:\Packages\Plugins\Microsoft.GuestConfiguration.ConfigurationforWindows\'
      -'\gc_worker.exe'

  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: medium