Hidden Powershell in Link File Pattern

 Original Source: [Sigma source]
Title: Hidden Powershell in Link File Pattern
Status: test
Description:Detects events that appear when a user click on a link file with a powershell command in it
References:
  -https://www.x86matthew.com/view_post?id=embed_exe_lnk
Author: frack113
Date: 2022-02-06
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage: 'C:\Windows\explorer.exe'
    Image: 'C:\Windows\System32\cmd.exe'
    CommandLine|contains|all:
      -'powershell'
      -'.lnk'

  condition:selection
Falsepositives:
  -Legitimate commands in .lnk files
Level: medium