{"id":"8d31a8ce-46b5-4dd6-bdc3-680931f1db86","title":"Bad Opsec Powershell Code Artifacts","description":"focuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including\nCobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads\nthat often undergo minimal changes by attackers due to bad opsec.\n","author":"ok @securonix invrep_de, oscd.community","status":"test","level":"critical","date":"2020-10-09","modified":"2022-12-25","tags":["attack.execution","attack.t1059.001"],"technique_ids":["T1059.001"],"logsource":{"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"},"falsepositives":["Moderate-to-low; Despite the shorter length/lower entropy for some of these, because of high specificity, fp appears to be fairly limited in many environments."],"references":["https://newtonpaul.com/analysing-fileless-malware-cobalt-strike-beacon/","https://labs.sentinelone.com/top-tier-russian-organized-cybercrime-group-unveils-fileless-stealthy-powertrick-backdoor-for-high-value-targets/","https://www.mdeditor.tw/pl/pgRt"],"source_path":"rules/windows/powershell/powershell_module/posh_pm_bad_opsec_artifacts.yml","source_sha256":"2395f144cbf1f1e363e06404c539589f1c8d159e5a9a540638cd7b771d6f070d","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_module/posh_pm_bad_opsec_artifacts.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Bad Opsec Powershell Code Artifacts\nid: 8d31a8ce-46b5-4dd6-bdc3-680931f1db86\nrelated:\n    - id: 73e733cc-1ace-3212-a107-ff2523cc9fc3\n      type: derived\nstatus: test\ndescription: |\n    focuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including\n    Cobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads\n    that often undergo minimal changes by attackers due to bad opsec.\nreferences:\n    - https://newtonpaul.com/analysing-fileless-malware-cobalt-strike-beacon/\n    - https://labs.sentinelone.com/top-tier-russian-organized-cybercrime-group-unveils-fileless-stealthy-powertrick-backdoor-for-high-value-targets/\n    - https://www.mdeditor.tw/pl/pgRt\nauthor: 'ok @securonix invrep_de, oscd.community'\ndate: 2020-10-09\nmodified: 2022-12-25\ntags:\n    - attack.execution\n    - attack.t1059.001\nlogsource:\n    product: windows\n    category: ps_module\n    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b\ndetection:\n    selection_4103:\n        Payload|contains:\n            - '$DoIt'\n            - 'harmj0y'\n            - 'mattifestation'\n            - '_RastaMouse'\n            - 'tifkin_'\n            - '0xdeadbeef'\n    condition: selection_4103\nfalsepositives:\n    - 'Moderate-to-low; Despite the shorter length/lower entropy for some of these, because of high specificity, fp appears to be fairly limited in many environments.'\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1059.001","id":"T1059.001","name":"PowerShell","page":"techniques/enterprise/T1059.001/"}],"data_path":"data/detection-rules/8d31a8ce-46b5-4dd6-bdc3-680931f1db86.json","kind":"sigma"}
