Suspicious PowerShell Parameter Substring

 Original Source: [Sigma source]
Title: Suspicious PowerShell Parameter Substring
Status: test
Description:Detects suspicious PowerShell invocation with a parameter substring
References:
  -http://www.danielbohannon.com/blog-1/2017/3/12/powershell-execution-argument-obfuscation-how-it-can-make-detection-easier
Author: Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix)
Date: 2019-01-16
modified:2022-07-14
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains:
      -' -windowstyle h '
      -' -windowstyl h'
      -' -windowsty h'
      -' -windowst h'
      -' -windows h'
      -' -windo h'
      -' -wind h'
      -' -win h'
      -' -wi h'
      -' -win h '
      -' -win hi '
      -' -win hid '
      -' -win hidd '
      -' -win hidde '
      -' -NoPr '
      -' -NoPro '
      -' -NoProf '
      -' -NoProfi '
      -' -NoProfil '
      -' -nonin '
      -' -nonint '
      -' -noninte '
      -' -noninter '
      -' -nonintera '
      -' -noninterac '
      -' -noninteract '
      -' -noninteracti '
      -' -noninteractiv '
      -' -ec '
      -' -encodedComman '
      -' -encodedComma '
      -' -encodedComm '
      -' -encodedCom '
      -' -encodedCo '
      -' -encodedC '
      -' -encoded '
      -' -encode '
      -' -encod '
      -' -enco '
      -' -en '
      -' -executionpolic '
      -' -executionpoli '
      -' -executionpol '
      -' -executionpo '
      -' -executionp '
      -' -execution bypass'
      -' -executio bypass'
      -' -executi bypass'
      -' -execut bypass'
      -' -execu bypass'
      -' -exec bypass'
      -' -exe bypass'
      -' -ex bypass'
      -' -ep bypass'
      -' /windowstyle h '
      -' /windowstyl h'
      -' /windowsty h'
      -' /windowst h'
      -' /windows h'
      -' /windo h'
      -' /wind h'
      -' /win h'
      -' /wi h'
      -' /win h '
      -' /win hi '
      -' /win hid '
      -' /win hidd '
      -' /win hidde '
      -' /NoPr '
      -' /NoPro '
      -' /NoProf '
      -' /NoProfi '
      -' /NoProfil '
      -' /nonin '
      -' /nonint '
      -' /noninte '
      -' /noninter '
      -' /nonintera '
      -' /noninterac '
      -' /noninteract '
      -' /noninteracti '
      -' /noninteractiv '
      -' /ec '
      -' /encodedComman '
      -' /encodedComma '
      -' /encodedComm '
      -' /encodedCom '
      -' /encodedCo '
      -' /encodedC '
      -' /encoded '
      -' /encode '
      -' /encod '
      -' /enco '
      -' /en '
      -' /executionpolic '
      -' /executionpoli '
      -' /executionpol '
      -' /executionpo '
      -' /executionp '
      -' /execution bypass'
      -' /executio bypass'
      -' /executi bypass'
      -' /execut bypass'
      -' /execu bypass'
      -' /exec bypass'
      -' /exe bypass'
      -' /ex bypass'
      -' /ep bypass'

  condition:selection
Falsepositives:
  -Unknown
Level: high