Name:Powershell Processing Stream Of Data id:0d718b52-c9f1-11eb-bc61-acde48001122 version:19 date:None author:Teoderick Contreras, Splunk status:production type:Anomaly Description:The following analytic detects suspicious PowerShell script execution involving compressed stream data processing, identified via EventCode 4104.
It leverages PowerShell Script Block Logging to flag scripts using `IO.Compression`, `IO.StreamReader`, or decompression methods.
This activity is significant as it often indicates obfuscated PowerShell or embedded .NET/binary execution, which are common tactics for evading detection.
If confirmed malicious, this behavior could allow attackers to execute hidden code, escalate privileges, or maintain persistence within the environment. Data_source:
-Powershell Script Block Logging 4104
search:`powershell` EventCode=4104 ScriptBlockText IN ( "*IO.Compression.*", "*IO.StreamReader*", "*]::Decompress*" ) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by dest signature signature_id user_id vendor_product EventID Guid Opcode Name Path ProcessID ScriptBlockId ScriptBlockText