Potential PowerShell Execution Via DLL

 Original Source: [Sigma source]
Title: Potential PowerShell Execution Via DLL
Status: test
Description:Detects potential PowerShell execution from a DLL instead of the usual PowerShell process as seen used in PowerShdll. This detection assumes that PowerShell commands are passed via the CommandLine.
References:
  -https://github.com/p3nt4/PowerShdll/blob/62cfa172fb4e1f7f4ac00ca942685baeb88ff356/README.md
Author: Markus Neis, Nasreddine Bencherchali (Nextron Systems)
Date: 2018-08-25
modified:2024-03-07
Tags:
  • -'attack.stealth'
  • -'attack.t1218.011'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\InstallUtil.exe'
      - '\RegAsm.exe'
      - '\RegSvcs.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
    - OriginalFileName:
      - 'InstallUtil.exe'
      - 'RegAsm.exe'
      - 'RegSvcs.exe'
      - 'REGSVR32.EXE'
      - 'RUNDLL32.EXE'
  selection_cli:
    CommandLine|contains:
      -'Default.GetString'
      -'DownloadString'
      -'FromBase64String'
      -'ICM '
      -'IEX '
      -'Invoke-Command'
      -'Invoke-Expression'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high