Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index

Flags obfuscated PowerShell scripts that enumerate ExportedCommands and invoke them indirectly using array indexing.

FreeReviewedSigma · Medium · v1
Product
windows
Category
ps_script
Author
Norbert Jaśniewicz (AlphaSOC) (SigmaHQ), DRL 1.1
Published
2026-10-06
Updated
2026-10-07

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags PowerShell script block text that enumerates Microsoft.PowerShell.Utility exported commands by using Get-Module/gmo with ListAvailable, ExportedCommands, and Values. It also requires evidence of array index usage patterns (ScriptBlockText containing [*]) to support indirect invocation. Such behavior can help attackers avoid detections that search for explicit cmdlet names by calling commands indirectly through an exported command list.

Related detections9 linkedT1027 — drag to rearrange
Suspicious PowerShell String Concatenation Obfuscation for Batch Extension via LNK (via process_creation)
Suspicious PowerShell Spawned from PyInstaller MEI Extraction Folder (via process_creation)
Suspicious PowerShell Encoded Command Execution
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Hidden PowerShell Executing Substring of Dropped File
Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index
Pivot detection · T1027 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.