Potentially Suspicious Powershell Script Execution From Temp Folder

 Original Source: [Sigma source]
Title: Potentially Suspicious Powershell Script Execution From Temp Folder
Status: test
Description:Detects a potentially suspicious powershell script executions from temporary folder
References:
  -https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton
Date: 2021-07-14
modified:2026-02-17
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains:
      -'\Windows\Temp'
      -'\Temporary Internet'
      -'\AppData\Local\Temp'
      -'\AppData\Roaming\Temp'
      -'%TEMP%'
      -'%TMP%'
      -'%LocalAppData%\Temp'

  filter_optional_vscode:
    CommandLine|contains: '-WindowStyle hidden -Verb runAs'
  filter_optional_amazon_ec2:
    CommandLine|contains: '\Windows\system32\config\systemprofile\AppData\Local\Temp\Amazon\EC2-Windows\'
  filter_optional_generic:
    CommandLine|contains:
      -' >'
      -'Out-File'
      -'ConvertTo-Json'

  filter_optional_chocolatey_installer:
    ParentImage:
      -'C:\Windows\System32\Msiexec.exe'
      -'C:\Windows\SysWOW64\Msiexec.exe'

    Image|endswith: '\powershell.exe'
    CommandLine|contains|all:
      -'-NoProfile -ExecutionPolicy Bypass -Command'
      -'AppData\Local\Temp\'
      -'Install-Chocolatey.ps1'

  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Administrative scripts
Level: medium