Loading interactive filters…
1200KM / detection
T1059.001 PowerShell — Detection Rules
Detection workspace for T1059.001 PowerShell: 179 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- AWS EC2 Startup Shell Script Change · test · high · {"product":"aws","service":"cloudtrail"}
- AppLocker Prevented Application or Script from Running · test · medium · {"product":"windows","service":"applocker"}
- Invoke-Obfuscation CLIP+ Launcher - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation STDIN+ Launcher - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation VAR+ Launcher - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security · test · medium · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation RUNDLL LAUNCHER - Security · test · medium · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation Via Stdin - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation Via Use Clip - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation Via Use MSHTA - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation Via Use Rundll32 - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Remote PowerShell Sessions Network Connections (WinRM) · test · high · {"product":"windows","service":"security"}
- Invoke-Obfuscation CLIP+ Launcher - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation STDIN+ Launcher - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation VAR+ Launcher - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation COMPRESS OBFUSCATION - System · test · medium · {"product":"windows","service":"system"}
- Invoke-Obfuscation RUNDLL LAUNCHER - System · test · medium · {"product":"windows","service":"system"}
- Invoke-Obfuscation Via Stdin - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation Via Use Clip - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation Via Use MSHTA - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation Via Use Rundll32 - System · test · high · {"product":"windows","service":"system"}
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System · test · high · {"product":"windows","service":"system"}
- Remote Thread Creation Via PowerShell In Uncommon Target · test · medium · {"product":"windows","category":"create_remote_thread"}
- BloodHound Collection Files · test · high · {"product":"windows","category":"file_event"}
- Malicious PowerShell Scripts - FileCreation · test · high · {"category":"file_event","product":"windows"}
- Suspicious Interactive PowerShell as SYSTEM · test · high · {"product":"windows","category":"file_event"}
- PowerShell Core DLL Loaded By Non PowerShell Process · test · medium · {"category":"image_load","product":"windows"}
- Suspicious WSMAN Provider Image Loads · test · medium · {"category":"image_load","product":"windows"}
- Potential Remote PowerShell Session Initiated · test · high · {"category":"network_connection","product":"windows"}
- Alternate PowerShell Hosts Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- New PowerShell Instance Created · test · informational · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- Nslookup PowerShell Download Cradle · test · medium · {"product":"windows","category":"ps_classic_start"}
- PowerShell Downgrade Attack - PowerShell · test · medium · {"product":"windows","category":"ps_classic_start"}
- PowerShell Download Via Net.WebClient - PowerShell Classic · test · low · {"product":"windows","category":"ps_classic_start"}
- PowerShell Called from an Executable Version Mismatch · test · high · {"product":"windows","category":"ps_classic_start"}
- Netcat The Powershell Version · test · medium · {"product":"windows","category":"ps_classic_start"}
- Remote PowerShell Session (PS Classic) · test · low · {"product":"windows","category":"ps_classic_start"}
- Renamed Powershell Under Powershell Channel · test · low · {"product":"windows","category":"ps_classic_start"}
- Suspicious Non PowerShell WSMAN COM Provider · test · medium · {"product":"windows","service":"powershell-classic"}
- Alternate PowerShell Hosts - PowerShell Module · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Bad Opsec Powershell Code Artifacts · test · critical · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Malicious PowerShell Scripts - PoshModule · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation Via Stdin - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation Via Use Clip - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Malicious PowerShell Commandlets - PoshModule · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Remote PowerShell Session (PS Module) · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Suspicious PowerShell Download - PoshModule · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Suspicious PowerShell Invocations - Generic - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Suspicious PowerShell Invocations - Specific - PowerShell Module · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- PowerShell ADRecon Execution · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Silence.EDA Detection · test · critical · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell Create Local User · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Import PowerShell Modules From Suspicious Directories · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation CLIP+ Launcher - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation STDIN+ Launcher - Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation VAR+ Launcher - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation Via Stdin - Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation Via Use Clip - Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation Via Use MSHTA - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation Via Use Rundll32 - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious PowerShell Commandlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious PowerShell Keywords · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Powershell MsXml COM Object · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious Nishang PowerShell Commandlets · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- NTFS Alternate Data Stream · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell Web Access Installation - PsScript · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerView PowerShell Cmdlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell Credential Prompt · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PSAsyncShell - Asynchronous TCP Reverse Shell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell PSAttack · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell Remote Session Creation · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Change PowerShell Policies to an Insecure Level - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- PowerShell ShellCode · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious ShellIntel PowerShell Commandlets · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential PowerShell Obfuscation Using Character Join · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious PowerShell Download - Powershell Script · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious PowerShell Invocations - Generic · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious PowerShell Invocations - Specific · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential Suspicious PowerShell Keywords · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential PowerShell Obfuscation Using Alias Cmdlets · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Usage Of Web Request Commands And Cmdlets - ScriptBlock · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential WinAPI Calls Via PowerShell Scripts · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- WMImplant Hack Tool · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Powershell XML Execute Command · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Remote LSASS Process Access Through Windows Remote Management · stable · high · {"category":"process_access","product":"windows"}
- Command Line Execution with Suspicious URL and AppData Strings · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious File Execution From Internet Hosted WebDav Share · test · high · {"category":"process_creation","product":"windows"}
- Cmd.EXE Missing Space Characters Execution Anomaly · test · high · {"category":"process_creation","product":"windows"}
- Powershell Executed From Headless ConHost Process · test · medium · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Bloodhound/Sharphound Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Covenant PowerShell Launcher · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution Patterns · stable · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec PowerShell Obfuscation · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Empire PowerShell Launch Parameters · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation CLIP+ Launcher · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation Obfuscated IEX Invocation · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation STDIN+ Launcher · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation VAR+ Launcher · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation COMPRESS OBFUSCATION · test · medium · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation Via Stdin · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation Via Use Clip · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation Via Use MSHTA · test · high · {"category":"process_creation","product":"windows"}
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Default PowerSploit/Empire Scheduled Task Creation · test · high · {"product":"windows","category":"process_creation"}
- Execute Code with Pester.bat as Parent · test · medium · {"category":"process_creation","product":"windows"}
- Execute Code with Pester.bat · test · medium · {"category":"process_creation","product":"windows"}
- Detection of PowerShell Execution via Sqlps.exe · test · medium · {"category":"process_creation","product":"windows"}
- SQL Client Tools PowerShell Session Detection · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Encoded PowerShell Command Line · test · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell Encoded Command Patterns · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded FromBase64String Cmdlet · test · high · {"category":"process_creation","product":"windows"}
- Malicious Base64 Encoded PowerShell Keywords in Command Lines · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded IEX Cmdlet · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded Invoke Keyword · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded Reflective Assembly Load · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded WMI Classes · test · high · {"category":"process_creation","product":"windows"}
- ConvertTo-SecureString Cmdlet Usage Via CommandLine · test · medium · {"category":"process_creation","product":"windows"}
- Potential PowerShell Obfuscation Via Reversed Commands · test · high · {"category":"process_creation","product":"windows"}
- Potential PowerShell Command Line Obfuscation · test · high · {"category":"process_creation","product":"windows"}
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · experimental · high · {"category":"process_creation","product":"windows"}
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential PowerShell Downgrade Attack · test · medium · {"category":"process_creation","product":"windows"}
- Obfuscated PowerShell OneLiner Execution · test · high · {"product":"windows","category":"process_creation"}
- Potential DLL File Download Via PowerShell Invoke-WebRequest · test · medium · {"product":"windows","category":"process_creation"}
- PowerShell Download Pattern · test · medium · {"category":"process_creation","product":"windows"}
- DSInternals Suspicious PowerShell Cmdlets · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Execution of Powershell with Base64 · test · medium · {"category":"process_creation","product":"windows"}
- Potential Encoded PowerShell Patterns In CommandLine · test · low · {"category":"process_creation","product":"windows"}
- Powershell Inline Execution From A File · test · medium · {"product":"windows","category":"process_creation"}
- Certificate Exported Via PowerShell · test · medium · {"product":"windows","category":"process_creation"}
- Base64 Encoded PowerShell Command Detected · test · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell IEX Execution Patterns · test · high · {"product":"windows","category":"process_creation"}
- Import PowerShell Modules From Suspicious Directories - ProcCreation · test · medium · {"category":"process_creation","product":"windows"}
- Malicious PowerShell Commandlets - ProcessCreation · test · high · {"category":"process_creation","product":"windows"}
- Non Interactive PowerShell Process Spawned · test · low · {"category":"process_creation","product":"windows"}
- Potential PowerShell Obfuscation Via WCHAR/CHAR · test · high · {"category":"process_creation","product":"windows"}
- Execution of Powershell Script in Public Folder · test · high · {"category":"process_creation","product":"windows"}
- Potential Powershell ReverseShell Connection · stable · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell Invocation From Script Engines · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Powershell Script Execution From Temp Folder · test · medium · {"category":"process_creation","product":"windows"}
- Change PowerShell Policies to an Insecure Level · test · medium · {"product":"windows","category":"process_creation"}
- Exchange PowerShell Snap-Ins Usage · test · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell Download and Execute Pattern · test · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell Parameter Substring · test · high · {"category":"process_creation","product":"windows"}
- Suspicious PowerShell Parent Process · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Script Run in AppData · test · medium · {"category":"process_creation","product":"windows"}
- Net WebClient Casing Anomalies · test · high · {"category":"process_creation","product":"windows"}
- Suspicious XOR Encoded PowerShell Command · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Schtasks Execution AppData Folder · test · high · {"product":"windows","category":"process_creation"}
- Potential Persistence Via Powershell Search Order Hijacking - Task · test · high · {"product":"windows","category":"process_creation"}
- Scheduled Task Executing Payload from Registry · test · medium · {"product":"windows","category":"process_creation"}
- Scheduled Task Executing Encoded Payload from Registry · test · high · {"product":"windows","category":"process_creation"}
- Potential Data Exfiltration Activity Via CommandLine Tools · test · high · {"category":"process_creation","product":"windows"}
- Hidden Powershell in Link File Pattern · test · medium · {"category":"process_creation","product":"windows"}
- Windows Shell/Scripting Processes Spawning Suspicious Programs · test · high · {"category":"process_creation","product":"windows"}
- Usage Of Web Request Commands And Cmdlets · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious WebDAV LNK Execution · test · medium · {"category":"process_creation","product":"windows"}
- Remote PowerShell Session Host Process (WinRM) · test · medium · {"category":"process_creation","product":"windows"}
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell · stable · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry · test · high · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
T1059.001 PowerShell
MATCH(powershell_execution) AND command_or_script MATCHES [encoded_command, download_expression, hidden_window, execution_policy_bypass] -> ALERT
Anomaly models
PowerShell script, encoded content, or remote command execution — T1059.001 PowerShell
Comparison unit: account-host-script combination.
Expected behavior: recurring administrative scripts use known modules, hosts, and execution paths.
Deviation: novel script features, uncommon account-host relationship, or unusual sequence of module and process activity.
ATT&CK analytic guidance
Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.