{"id":"41025fd7-0466-4650-a813-574aaacbe7f4","title":"Malicious PowerShell Scripts - PoshModule","description":"Detects the execution of known offensive powershell scripts used for exploitation or reconnaissance","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-23","modified":"2025-12-10","tags":["attack.execution","attack.t1059.001"],"technique_ids":["T1059.001"],"logsource":{"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"},"falsepositives":["Unknown"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://github.com/NetSPI/PowerUpSQL","https://github.com/CsEnox/EventViewer-UACBypass","https://web.archive.org/web/20210511204621/https://github.com/AlsidOfficial/WSUSpendu","https://github.com/nettitude/Invoke-PowerThIEf","https://github.com/S3cur3Th1sSh1t/WinPwn","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"source_path":"rules/windows/powershell/powershell_module/posh_pm_exploit_scripts.yml","source_sha256":"0805f4f0e1bf8a5cbd906ece4da6c1af93ddc064fd755d48086b31e5f4c64e36","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_module/posh_pm_exploit_scripts.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Malicious PowerShell Scripts - PoshModule\nid: 41025fd7-0466-4650-a813-574aaacbe7f4\nrelated:\n    - id: f331aa1f-8c53-4fc3-b083-cc159bc971cb\n      type: similar\n    - id: bf7286e7-c0be-460b-a7e8-5b2e07ecc2f2\n      type: obsolete\nstatus: test\ndescription: Detects the execution of known offensive powershell scripts used for exploitation or reconnaissance\nreferences:\n    - https://github.com/PowerShellMafia/PowerSploit\n    - https://github.com/NetSPI/PowerUpSQL\n    - https://github.com/CsEnox/EventViewer-UACBypass\n    - https://web.archive.org/web/20210511204621/https://github.com/AlsidOfficial/WSUSpendu\n    - https://github.com/nettitude/Invoke-PowerThIEf\n    - https://github.com/S3cur3Th1sSh1t/WinPwn\n    - https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries\n    - https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1\n    - https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1\n    - https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1\n    - https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1\n    - https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/ # Invoke-TotalExec\n    - https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/ # Invoke-TotalExec\n    - https://github.com/HarmJ0y/DAMP\n    - https://github.com/samratashok/nishang\n    - https://github.com/DarkCoderSc/PowerRunAsSystem/\n    - https://github.com/besimorhino/powercat\n    - https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1\n    - https://github.com/The-Viper-One/Invoke-PowerDPAPI/\n    - https://github.com/Arno0x/DNSExfiltrator/\nauthor: frack113, Nasreddine Bencherchali (Nextron Systems)\ndate: 2023-01-23\nmodified: 2025-12-10\ntags:\n    - attack.execution\n    - attack.t1059.001\nlogsource:\n    product: windows\n    category: ps_module\n    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b\ndetection:\n    selection_generic:\n        ContextInfo|contains:\n            - 'Add-ConstrainedDelegationBackdoor.ps1'\n            - 'Add-Exfiltration.ps1'\n            - 'Add-Persistence.ps1'\n            - 'Add-RegBackdoor.ps1'\n            - 'Add-RemoteRegBackdoor.ps1'\n            - 'Add-ScrnSaveBackdoor.ps1'\n            - 'BadSuccessor.ps1'\n            - 'Check-VM.ps1'\n            - 'ConvertTo-ROT13.ps1'\n            - 'Copy-VSS.ps1'\n            - 'Create-MultipleSessions.ps1'\n            - 'DNS_TXT_Pwnage.ps1'\n            - 'dnscat2.ps1'\n            - 'Do-Exfiltration.ps1'\n            - 'DomainPasswordSpray.ps1'\n            - 'Download_Execute.ps1'\n            - 'Download-Execute-PS.ps1'\n            - 'Enabled-DuplicateToken.ps1'\n            - 'Enable-DuplicateToken.ps1'\n            - 'Execute-Command-MSSQL.ps1'\n            - 'Execute-DNSTXT-Code.ps1'\n            - 'Execute-OnTime.ps1'\n            - 'ExetoText.ps1'\n            - 'Exploit-Jboss.ps1'\n            - 'Find-AVSignature.ps1'\n            - 'Find-Fruit.ps1'\n            - 'Find-GPOLocation.ps1'\n            - 'Find-TrustedDocuments.ps1'\n            - 'FireBuster.ps1'\n            - 'FireListener.ps1'\n            - 'Get-ApplicationHost.ps1'\n            - 'Get-ChromeDump.ps1'\n            - 'Get-ClipboardContents.ps1'\n            - 'Get-ComputerDetail.ps1'\n            - 'Get-FoxDump.ps1'\n            - 'Get-GPPAutologon.ps1'\n            - 'Get-GPPPassword.ps1'\n            - 'Get-IndexedItem.ps1'\n            - 'Get-Keystrokes.ps1'\n            - 'Get-LSASecret.ps1'\n            - 'Get-MicrophoneAudio.ps1'\n            - 'Get-PassHashes.ps1'\n            - 'Get-PassHints.ps1'\n            - 'Get-RegAlwaysInstallElevated.ps1'\n            - 'Get-RegAutoLogon.ps1'\n            - 'Get-RickAstley.ps1'\n            - 'Get-Screenshot.ps1'\n            - 'Get-SecurityPackages.ps1'\n            - 'Get-ServiceFilePermission.ps1'\n            - 'Get-ServicePermission.ps1'\n            - 'Get-ServiceUnquoted.ps1'\n            - 'Get-SiteListPassword.ps1'\n            - 'Get-System.ps1'\n            - 'Get-TimedScreenshot.ps1'\n            - 'Get-UnattendedInstallFile.ps1'\n            - 'Get-Unconstrained.ps1'\n            - 'Get-USBKeystrokes.ps1'\n            - 'Get-VaultCredential.ps1'\n            - 'Get-VulnAutoRun.ps1'\n            - 'Get-VulnSchTask.ps1'\n            - 'Get-WebConfig.ps1'\n            - 'Get-WebCredentials.ps1'\n            - 'Get-WLAN-Keys.ps1'\n            - 'Gupt-Backdoor.ps1'\n            - 'HTTP-Backdoor.ps1'\n            - 'HTTP-Login.ps1'\n            - 'Install-ServiceBinary.ps1'\n            - 'Install-SSP.ps1'\n            - 'Invoke-ACLScanner.ps1'\n            - 'Invoke-ADSBackdoor.ps1'\n            - 'Invoke-AmsiBypass.ps1'\n            - 'Invoke-ARPScan.ps1'\n            - 'Invoke-BackdoorLNK.ps1'\n            - 'Invoke-BadPotato.ps1'\n            - 'Invoke-BetterSafetyKatz.ps1'\n            - 'Invoke-BruteForce.ps1'\n            - 'Invoke-BypassUAC.ps1'\n            - 'Invoke-Carbuncle.ps1'\n            - 'Invoke-Certify.ps1'\n            - 'Invoke-ConPtyShell.ps1'\n            - 'Invoke-CredentialInjection.ps1'\n            - 'Invoke-CredentialsPhish.ps1'\n            - 'Invoke-DAFT.ps1'\n            - 'Invoke-DCSync.ps1'\n            - 'Invoke-Decode.ps1'\n            - 'Invoke-DinvokeKatz.ps1'\n            - 'Invoke-DllInjection.ps1'\n            - 'Invoke-DNSExfiltrator.ps1'\n            - 'Invoke-DowngradeAccount.ps1'\n            - 'Invoke-EgressCheck.ps1'\n            - 'Invoke-Encode.ps1'\n            - 'Invoke-EventViewer.ps1'\n            - 'Invoke-Eyewitness.ps1'\n            - 'Invoke-FakeLogonScreen.ps1'\n            - 'Invoke-Farmer.ps1'\n            - 'Invoke-Get-RBCD-Threaded.ps1'\n            - 'Invoke-Gopher.ps1'\n            - 'Invoke-Grouper2.ps1'\n            - 'Invoke-Grouper3.ps1'\n            - 'Invoke-HandleKatz.ps1'\n            - 'Invoke-Interceptor.ps1'\n            - 'Invoke-Internalmonologue.ps1'\n            - 'Invoke-Inveigh.ps1'\n            - 'Invoke-InveighRelay.ps1'\n            - 'Invoke-JSRatRegsvr.ps1'\n            - 'Invoke-JSRatRundll.ps1'\n            - 'Invoke-KrbRelay.ps1'\n            - 'Invoke-KrbRelayUp.ps1'\n            - 'Invoke-LdapSignCheck.ps1'\n            - 'Invoke-Lockless.ps1'\n            - 'Invoke-MalSCCM.ps1'\n            - 'Invoke-Mimikatz.ps1'\n            - 'Invoke-MimikatzWDigestDowngrade.ps1'\n            - 'Invoke-Mimikittenz.ps1'\n            - 'Invoke-MITM6.ps1'\n            - 'Invoke-NanoDump.ps1'\n            - 'Invoke-NetRipper.ps1'\n            - 'Invoke-NetworkRelay.ps1'\n            - 'Invoke-NinjaCopy.ps1'\n            - 'Invoke-OxidResolver.ps1'\n            - 'Invoke-P0wnedshell.ps1'\n            - 'Invoke-P0wnedshellx86.ps1'\n            - 'Invoke-Paranoia.ps1'\n            - 'Invoke-PortScan.ps1'\n            - 'Invoke-PoshRatHttp.ps1'\n            - 'Invoke-PoshRatHttps.ps1'\n            - 'Invoke-PostExfil.ps1'\n            - 'Invoke-PowerDump.ps1'\n            - 'Invoke-PowerDPAPI.ps1'\n            - 'Invoke-PowerShellIcmp.ps1'\n            - 'Invoke-PowerShellTCP.ps1'\n            - 'Invoke-PowerShellTcpOneLine.ps1'\n            - 'Invoke-PowerShellTcpOneLineBind.ps1'\n            - 'Invoke-PowerShellUdp.ps1'\n            - 'Invoke-PowerShellUdpOneLine.ps1'\n            - 'Invoke-PowerShellWMI.ps1'\n            - 'Invoke-PowerThIEf.ps1'\n            - 'Invoke-PPLDump.ps1'\n            - 'Invoke-Prasadhak.ps1'\n            - 'Invoke-PsExec.ps1'\n            - 'Invoke-PsGcat.ps1'\n            - 'Invoke-PsGcatAgent.ps1'\n            - 'Invoke-PSInject.ps1'\n            - 'Invoke-PsUaCme.ps1'\n            - 'Invoke-ReflectivePEInjection.ps1'\n            - 'Invoke-ReverseDNSLookup.ps1'\n            - 'Invoke-Rubeus.ps1'\n            - 'Invoke-RunAs.ps1'\n            - 'Invoke-SafetyKatz.ps1'\n            - 'Invoke-SauronEye.ps1'\n            - 'Invoke-SCShell.ps1'\n            - 'Invoke-Seatbelt.ps1'\n            - 'Invoke-ServiceAbuse.ps1'\n            - 'Invoke-SessionGopher.ps1'\n            - 'Invoke-ShellCode.ps1'\n            - 'Invoke-SMBScanner.ps1'\n            - 'Invoke-Snaffler.ps1'\n            - 'Invoke-Spoolsample.ps1'\n            - 'Invoke-SSHCommand.ps1'\n            - 'Invoke-SSIDExfil.ps1'\n            - 'Invoke-StandIn.ps1'\n            - 'Invoke-StickyNotesExtract.ps1'\n            - 'Invoke-Tater.ps1'\n            - 'Invoke-Thunderfox.ps1'\n            - 'Invoke-ThunderStruck.ps1'\n            - 'Invoke-TokenManipulation.ps1'\n            - 'Invoke-Tokenvator.ps1'\n            - 'Invoke-TotalExec.ps1'\n            - 'Invoke-UrbanBishop.ps1'\n            - 'Invoke-UserHunter.ps1'\n            - 'Invoke-VoiceTroll.ps1'\n            - 'Invoke-Whisker.ps1'\n            - 'Invoke-WinEnum.ps1'\n            - 'Invoke-winPEAS.ps1'\n            - 'Invoke-WireTap.ps1'\n            - 'Invoke-WmiCommand.ps1'\n            - 'Invoke-WScriptBypassUAC.ps1'\n            - 'Invoke-Zerologon.ps1'\n            - 'Keylogger.ps1'\n            - 'MailRaider.ps1'\n            - 'New-HoneyHash.ps1'\n            - 'OfficeMemScraper.ps1'\n            - 'Offline_Winpwn.ps1'\n            - 'Out-CHM.ps1'\n            - 'Out-DnsTxt.ps1'\n            - 'Out-Excel.ps1'\n            - 'Out-HTA.ps1'\n            - 'Out-Java.ps1'\n            - 'Out-JS.ps1'\n            - 'Out-Minidump.ps1'\n            - 'Out-RundllCommand.ps1'\n            - 'Out-SCF.ps1'\n            - 'Out-SCT.ps1'\n            - 'Out-Shortcut.ps1'\n            - 'Out-WebQuery.ps1'\n            - 'Out-Word.ps1'\n            - 'Parse_Keys.ps1'\n            - 'Port-Scan.ps1'\n            - 'PowerBreach.ps1'\n            - 'powercat.ps1'\n            - 'PowerRunAsSystem.psm1'\n            - 'PowerSharpPack.ps1'\n            - 'PowerUp.ps1'\n            - 'PowerUpSQL.ps1'\n            - 'PowerView.ps1'\n            - 'PSAsyncShell.ps1'\n            - 'RemoteHashRetrieval.ps1'\n            - 'Remove-Persistence.ps1'\n            - 'Remove-PoshRat.ps1'\n            - 'Remove-Update.ps1'\n            - 'Run-EXEonRemote.ps1'\n            - 'Schtasks-Backdoor.ps1'\n            - 'Set-DCShadowPermissions.ps1'\n            - 'Set-MacAttribute.ps1'\n            - 'Set-RemotePSRemoting.ps1'\n            - 'Set-RemoteWMI.ps1'\n            - 'Set-Wallpaper.ps1'\n            - 'Show-TargetScreen.ps1'\n            - 'Speak.ps1'\n            - 'Start-CaptureServer.ps1'\n            - 'Start-WebcamRecorder.ps1'\n            - 'StringToBase64.ps1'\n            - 'TexttoExe.ps1'\n            - 'Veeam-Get-Creds.ps1'\n            - 'VolumeShadowCopyTools.ps1'\n            - 'WinPwn.ps1'\n            - 'WSUSpendu.ps1'\n    selection_invoke_sharp:\n        ContextInfo|contains|all:\n            - 'Invoke-Sharp' # Covers all \"Invoke-Sharp\" variants\n            - '.ps1'\n    condition: 1 of selection_*\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1059.001","id":"T1059.001","name":"PowerShell","page":"techniques/enterprise/T1059.001/"}],"data_path":"data/detection-rules/41025fd7-0466-4650-a813-574aaacbe7f4.json","kind":"sigma"}
