T1059.001 PowerShell
Sub-technique of T1059 Command and Scripting Interpreter
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Bad Opsec Powershell Code Artifactscriticaltest · windows
- Greenbug Espionage Group Indicatorscriticaltest · windows
- Rorschach Ransomware Execution Activitycriticaltest · windows
- Silence.EDA Detectioncriticaltest · windows
- Turla Group Commands May 2020criticaltest · windows
- UNC2452 PowerShell Patterncriticaltest · windows
- HackTool - CrackMapExec Execution Patternshighstable · windows
- Potential Emotet Activityhighstable · windows
- Potential Powershell ReverseShell Connectionhighstable · windows
- Remote LSASS Process Access Through Windows Remote Managementhighstable · windows
- TropicTrooper Campaign November 2018highstable · windows
- AWS EC2 Startup Shell Script Changehightest · aws
- Base64 Encoded PowerShell Command Detectedhightest · windows
- BloodHound Collection Fileshightest · windows
- CVE-2022-24527 Microsoft Connected Cache LPEhightest · windows
- ChromeLoader Malware Executionhightest · windows
- Cmd.EXE Missing Space Characters Execution Anomalyhightest · windows
- DSInternals Suspicious PowerShell Cmdletshightest · windows
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlockhightest · windows
- Exchange PowerShell Snap-Ins Usagehightest · windows
- Execution of Powershell Script in Public Folderhightest · windows
- Exploited CVE-2020-10189 Zoho ManageEnginehightest · windows
- FakeUpdates/SocGholish Activityhightest · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- HackTool - Bloodhound/Sharphound Executionhightest · windows
Showing 25 of 40.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.