{"id":"f331aa1f-8c53-4fc3-b083-cc159bc971cb","title":"Malicious PowerShell Scripts - FileCreation","description":"Detects the creation of known offensive powershell scripts used for exploitation","author":"Markus Neis, Nasreddine Bencherchali (Nextron Systems), Mustafa Kaan Demir, Georg Lauenstein","status":"test","level":"high","date":"2018-04-07","modified":"2025-12-10","tags":["attack.execution","attack.t1059.001"],"technique_ids":["T1059.001"],"logsource":{"category":"file_event","product":"windows"},"falsepositives":["Unknown"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://github.com/NetSPI/PowerUpSQL","https://github.com/CsEnox/EventViewer-UACBypass","https://web.archive.org/web/20210511204621/https://github.com/AlsidOfficial/WSUSpendu","https://github.com/nettitude/Invoke-PowerThIEf","https://github.com/S3cur3Th1sSh1t/WinPwn","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"source_path":"rules/windows/file/file_event/file_event_win_powershell_exploit_scripts.yml","source_sha256":"1e7bdc7dcc5e4d88787eb5d717511ca1f32f3b4b81befec6bf4b4b555c070c00","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_powershell_exploit_scripts.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Malicious PowerShell Scripts - FileCreation\nid: f331aa1f-8c53-4fc3-b083-cc159bc971cb\nrelated:\n    - id: 41025fd7-0466-4650-a813-574aaacbe7f4\n      type: similar\nstatus: test\ndescription: Detects the creation of known offensive powershell scripts used for exploitation\nreferences:\n    - https://github.com/PowerShellMafia/PowerSploit\n    - https://github.com/NetSPI/PowerUpSQL\n    - https://github.com/CsEnox/EventViewer-UACBypass\n    - https://web.archive.org/web/20210511204621/https://github.com/AlsidOfficial/WSUSpendu\n    - https://github.com/nettitude/Invoke-PowerThIEf\n    - https://github.com/S3cur3Th1sSh1t/WinPwn\n    - https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries\n    - https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1\n    - https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1\n    - https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1\n    - https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1\n    - https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/ # Invoke-TotalExec\n    - https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/ # Invoke-TotalExec\n    - https://github.com/HarmJ0y/DAMP\n    - https://github.com/samratashok/nishang\n    - https://github.com/DarkCoderSc/PowerRunAsSystem/\n    - https://github.com/besimorhino/powercat\n    - https://github.com/Kevin-Robertson/Powermad\n    - https://github.com/adrecon/ADRecon\n    - https://github.com/adrecon/AzureADRecon\n    - https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1\n    - https://github.com/The-Viper-One/Invoke-PowerDPAPI/\n    - https://github.com/Arno0x/DNSExfiltrator/\nauthor: Markus Neis, Nasreddine Bencherchali (Nextron Systems), Mustafa Kaan Demir, Georg Lauenstein\ndate: 2018-04-07\nmodified: 2025-12-10\ntags:\n    - attack.execution\n    - attack.t1059.001\nlogsource:\n    category: file_event\n    product: windows\ndetection:\n    selection_generic:\n        TargetFilename|endswith:\n            # Note: Please ensure alphabetical order when adding new entries\n            - '\\Add-ConstrainedDelegationBackdoor.ps1'\n            - '\\Add-Exfiltration.ps1'\n            - '\\Add-Persistence.ps1'\n            - '\\Add-RegBackdoor.ps1'\n            - '\\Add-RemoteRegBackdoor.ps1'\n            - '\\Add-ScrnSaveBackdoor.ps1'\n            - '\\ADRecon.ps1'\n            - '\\AzureADRecon.ps1'\n            - '\\BadSuccessor.ps1'\n            - '\\Check-VM.ps1'\n            - '\\ConvertTo-ROT13.ps1'\n            - '\\Copy-VSS.ps1'\n            - '\\Create-MultipleSessions.ps1'\n            - '\\DNS_TXT_Pwnage.ps1'\n            - '\\dnscat2.ps1'\n            - '\\Do-Exfiltration.ps1'\n            - '\\DomainPasswordSpray.ps1'\n            - '\\Download_Execute.ps1'\n            - '\\Download-Execute-PS.ps1'\n            - '\\Enable-DuplicateToken.ps1'\n            - '\\Enabled-DuplicateToken.ps1'\n            - '\\Execute-Command-MSSQL.ps1'\n            - '\\Execute-DNSTXT-Code.ps1'\n            - '\\Execute-OnTime.ps1'\n            - '\\ExetoText.ps1'\n            - '\\Exploit-Jboss.ps1'\n            - '\\Find-AVSignature.ps1'\n            - '\\Find-Fruit.ps1'\n            - '\\Find-GPOLocation.ps1'\n            - '\\Find-TrustedDocuments.ps1'\n            - '\\FireBuster.ps1'\n            - '\\FireListener.ps1'\n            - '\\Get-ApplicationHost.ps1'\n            - '\\Get-ChromeDump.ps1'\n            - '\\Get-ClipboardContents.ps1'\n            - '\\Get-ComputerDetail.ps1'\n            - '\\Get-FoxDump.ps1'\n            - '\\Get-GPPAutologon.ps1'\n            - '\\Get-GPPPassword.ps1'\n            - '\\Get-IndexedItem.ps1'\n            - '\\Get-Keystrokes.ps1'\n            - '\\Get-LSASecret.ps1'\n            - '\\Get-MicrophoneAudio.ps1'\n            - '\\Get-PassHashes.ps1'\n            - '\\Get-PassHints.ps1'\n            - '\\Get-RegAlwaysInstallElevated.ps1'\n            - '\\Get-RegAutoLogon.ps1'\n            - '\\Get-RickAstley.ps1'\n            - '\\Get-Screenshot.ps1'\n            - '\\Get-SecurityPackages.ps1'\n            - '\\Get-ServiceFilePermission.ps1'\n            - '\\Get-ServicePermission.ps1'\n            - '\\Get-ServiceUnquoted.ps1'\n            - '\\Get-SiteListPassword.ps1'\n            - '\\Get-System.ps1'\n            - '\\Get-TimedScreenshot.ps1'\n            - '\\Get-UnattendedInstallFile.ps1'\n            - '\\Get-Unconstrained.ps1'\n            - '\\Get-USBKeystrokes.ps1'\n            - '\\Get-VaultCredential.ps1'\n            - '\\Get-VulnAutoRun.ps1'\n            - '\\Get-VulnSchTask.ps1'\n            - '\\Get-WebConfig.ps1'\n            - '\\Get-WebCredentials.ps1'\n            - '\\Get-WLAN-Keys.ps1'\n            - '\\Gupt-Backdoor.ps1'\n            - '\\HTTP-Backdoor.ps1'\n            - '\\HTTP-Login.ps1'\n            - '\\Install-ServiceBinary.ps1'\n            - '\\Install-SSP.ps1'\n            - '\\Invoke-ACLScanner.ps1'\n            - '\\Invoke-ADSBackdoor.ps1'\n            - '\\Invoke-AmsiBypass.ps1'\n            - '\\Invoke-ARPScan.ps1'\n            - '\\Invoke-BackdoorLNK.ps1'\n            - '\\Invoke-BadPotato.ps1'\n            - '\\Invoke-BetterSafetyKatz.ps1'\n            - '\\Invoke-BruteForce.ps1'\n            - '\\Invoke-BypassUAC.ps1'\n            - '\\Invoke-Carbuncle.ps1'\n            - '\\Invoke-Certify.ps1'\n            - '\\Invoke-ConPtyShell.ps1'\n            - '\\Invoke-CredentialInjection.ps1'\n            - '\\Invoke-CredentialsPhish.ps1'\n            - '\\Invoke-DAFT.ps1'\n            - '\\Invoke-DCSync.ps1'\n            - '\\Invoke-Decode.ps1'\n            - '\\Invoke-DinvokeKatz.ps1'\n            - '\\Invoke-DllInjection.ps1'\n            - '\\Invoke-DNSExfiltrator.ps1'\n            - '\\Invoke-DNSUpdate.ps1'\n            - '\\Invoke-DowngradeAccount.ps1'\n            - '\\Invoke-EgressCheck.ps1'\n            - '\\Invoke-Encode.ps1'\n            - '\\Invoke-EventViewer.ps1'\n            - '\\Invoke-Eyewitness.ps1'\n            - '\\Invoke-FakeLogonScreen.ps1'\n            - '\\Invoke-Farmer.ps1'\n            - '\\Invoke-Get-RBCD-Threaded.ps1'\n            - '\\Invoke-Gopher.ps1'\n            - '\\Invoke-Grouper2.ps1'\n            - '\\Invoke-Grouper3.ps1'\n            - '\\Invoke-HandleKatz.ps1'\n            - '\\Invoke-Interceptor.ps1'\n            - '\\Invoke-Internalmonologue.ps1'\n            - '\\Invoke-Inveigh.ps1'\n            - '\\Invoke-InveighRelay.ps1'\n            - '\\Invoke-JSRatRegsvr.ps1'\n            - '\\Invoke-JSRatRundll.ps1'\n            - '\\Invoke-KrbRelay.ps1'\n            - '\\Invoke-KrbRelayUp.ps1'\n            - '\\Invoke-LdapSignCheck.ps1'\n            - '\\Invoke-Lockless.ps1'\n            - '\\Invoke-MalSCCM.ps1'\n            - '\\Invoke-Mimikatz.ps1'\n            - '\\Invoke-MimikatzWDigestDowngrade.ps1'\n            - '\\Invoke-Mimikittenz.ps1'\n            - '\\Invoke-MITM6.ps1'\n            - '\\Invoke-NanoDump.ps1'\n            - '\\Invoke-NetRipper.ps1'\n            - '\\Invoke-NetworkRelay.ps1'\n            - '\\Invoke-NinjaCopy.ps1'\n            - '\\Invoke-OxidResolver.ps1'\n            - '\\Invoke-P0wnedshell.ps1'\n            - '\\Invoke-P0wnedshellx86.ps1'\n            - '\\Invoke-Paranoia.ps1'\n            - '\\Invoke-PortScan.ps1'\n            - '\\Invoke-PoshRatHttp.ps1'\n            - '\\Invoke-PoshRatHttps.ps1'\n            - '\\Invoke-PostExfil.ps1'\n            - '\\Invoke-PowerDump.ps1'\n            - '\\Invoke-PowerDPAPI.ps1'\n            - '\\Invoke-PowerShellIcmp.ps1'\n            - '\\Invoke-PowerShellTCP.ps1'\n            - '\\Invoke-PowerShellTcpOneLine.ps1'\n            - '\\Invoke-PowerShellTcpOneLineBind.ps1'\n            - '\\Invoke-PowerShellUdp.ps1'\n            - '\\Invoke-PowerShellUdpOneLine.ps1'\n            - '\\Invoke-PowerShellWMI.ps1'\n            - '\\Invoke-PowerThIEf.ps1'\n            - '\\Invoke-PPLDump.ps1'\n            - '\\Invoke-Prasadhak.ps1'\n            - '\\Invoke-PsExec.ps1'\n            - '\\Invoke-PsGcat.ps1'\n            - '\\Invoke-PsGcatAgent.ps1'\n            - '\\Invoke-PSInject.ps1'\n            - '\\Invoke-PsUaCme.ps1'\n            - '\\Invoke-ReflectivePEInjection.ps1'\n            - '\\Invoke-ReverseDNSLookup.ps1'\n            - '\\Invoke-Rubeus.ps1'\n            - '\\Invoke-RunAs.ps1'\n            - '\\Invoke-SafetyKatz.ps1'\n            - '\\Invoke-SauronEye.ps1'\n            - '\\Invoke-SCShell.ps1'\n            - '\\Invoke-Seatbelt.ps1'\n            - '\\Invoke-ServiceAbuse.ps1'\n            - '\\Invoke-SessionGopher.ps1'\n            - '\\Invoke-ShellCode.ps1'\n            - '\\Invoke-SMBScanner.ps1'\n            - '\\Invoke-Snaffler.ps1'\n            - '\\Invoke-Spoolsample.ps1'\n            - '\\Invoke-SSHCommand.ps1'\n            - '\\Invoke-SSIDExfil.ps1'\n            - '\\Invoke-StandIn.ps1'\n            - '\\Invoke-StickyNotesExtract.ps1'\n            - '\\Invoke-Tater.ps1'\n            - '\\Invoke-Thunderfox.ps1'\n            - '\\Invoke-ThunderStruck.ps1'\n            - '\\Invoke-TokenManipulation.ps1'\n            - '\\Invoke-Tokenvator.ps1'\n            - '\\Invoke-TotalExec.ps1'\n            - '\\Invoke-UrbanBishop.ps1'\n            - '\\Invoke-UserHunter.ps1'\n            - '\\Invoke-VoiceTroll.ps1'\n            - '\\Invoke-Whisker.ps1'\n            - '\\Invoke-WinEnum.ps1'\n            - '\\Invoke-winPEAS.ps1'\n            - '\\Invoke-WireTap.ps1'\n            - '\\Invoke-WmiCommand.ps1'\n            - '\\Invoke-WScriptBypassUAC.ps1'\n            - '\\Invoke-Zerologon.ps1'\n            - '\\Keylogger.ps1'\n            - '\\MailRaider.ps1'\n            - '\\New-HoneyHash.ps1'\n            - '\\OfficeMemScraper.ps1'\n            - '\\Offline_Winpwn.ps1'\n            - '\\Out-CHM.ps1'\n            - '\\Out-DnsTxt.ps1'\n            - '\\Out-Excel.ps1'\n            - '\\Out-HTA.ps1'\n            - '\\Out-Java.ps1'\n            - '\\Out-JS.ps1'\n            - '\\Out-Minidump.ps1'\n            - '\\Out-RundllCommand.ps1'\n            - '\\Out-SCF.ps1'\n            - '\\Out-SCT.ps1'\n            - '\\Out-Shortcut.ps1'\n            - '\\Out-WebQuery.ps1'\n            - '\\Out-Word.ps1'\n            - '\\Parse_Keys.ps1'\n            - '\\Port-Scan.ps1'\n            - '\\PowerBreach.ps1'\n            - '\\powercat.ps1'\n            - '\\Powermad.ps1'\n            - '\\PowerRunAsSystem.psm1'\n            - '\\PowerSharpPack.ps1'\n            - '\\PowerUp.ps1'\n            - '\\PowerUpSQL.ps1'\n            - '\\PowerView.ps1'\n            - '\\PSAsyncShell.ps1'\n            - '\\RemoteHashRetrieval.ps1'\n            - '\\Remove-Persistence.ps1'\n            - '\\Remove-PoshRat.ps1'\n            - '\\Remove-Update.ps1'\n            - '\\Run-EXEonRemote.ps1'\n            - '\\Schtasks-Backdoor.ps1'\n            - '\\Set-DCShadowPermissions.ps1'\n            - '\\Set-MacAttribute.ps1'\n            - '\\Set-RemotePSRemoting.ps1'\n            - '\\Set-RemoteWMI.ps1'\n            - '\\Set-Wallpaper.ps1'\n            - '\\Show-TargetScreen.ps1'\n            - '\\Speak.ps1'\n            - '\\Start-CaptureServer.ps1'\n            - '\\Start-WebcamRecorder.ps1'\n            - '\\StringToBase64.ps1'\n            - '\\TexttoExe.ps1'\n            - '\\Veeam-Get-Creds.ps1'\n            - '\\VolumeShadowCopyTools.ps1'\n            - '\\WinPwn.ps1'\n            - '\\WSUSpendu.ps1'\n    selection_invoke_sharp:\n        TargetFilename|contains: 'Invoke-Sharp' # Covers all \"Invoke-Sharp\" variants\n        TargetFilename|endswith: '.ps1'\n    condition: 1 of selection_*\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1059.001","id":"T1059.001","name":"PowerShell","page":"techniques/enterprise/T1059.001/"}],"data_path":"data/detection-rules/f331aa1f-8c53-4fc3-b083-cc159bc971cb.json","kind":"sigma"}
