Potential Encoded PowerShell Patterns In CommandLine

 Original Source: [Sigma source]
Title: Potential Encoded PowerShell Patterns In CommandLine
Status: test
Description:Detects specific combinations of encoding methods in PowerShell via the commandline
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=65
Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton
Date: 2020-10-11
modified:2023-01-26
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_to_1:
    CommandLine|contains:
      -'ToInt'
      -'ToDecimal'
      -'ToByte'
      -'ToUint'
      -'ToSingle'
      -'ToSByte'

  selection_to_2:
    CommandLine|contains:
      -'ToChar'
      -'ToString'
      -'String'

  selection_gen_1:
    CommandLine|contains|all:
      -'char'
      -'join'

  selection_gen_2:
    CommandLine|contains|all:
      -'split'
      -'join'

  condition:selection_img and (all of selection_to_* or 1 of selection_gen_*)
Falsepositives:
  -Unknown
Level: low