Suspicious PowerShell IEX Execution Patterns

 Original Source: [Sigma source]
Title: Suspicious PowerShell IEX Execution Patterns
Status: test
Description:Detects suspicious ways to run Invoke-Execution using IEX alias
References:
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-expression?view=powershell-7.2
  -https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-03-24
modified:2022-11-28
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_combined_1:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains:
      -' | iex;'
      -' | iex '
      -' | iex}'
      -' | IEX ;'
      -' | IEX -Error'
      -' | IEX (new'
      -');IEX '

  selection_combined_2:
    CommandLine|contains:
      -'::FromBase64String'
      -'.GetString([System.Convert]::'

  selection_standalone:
    CommandLine|contains:
      -')|iex;$'
      -');iex($'
      -');iex $'
      -' | IEX | '
      -' | iex\"'

  condition:all of selection_combined_* or selection_standalone
Falsepositives:
  -Legitimate scripts that use IEX
Level: high