Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index
Flags obfuscated PowerShell scripts that enumerate ExportedCommands and invoke them indirectly using array indexing.
- Product
- windows
- Category
- ps_script
- Author
- Norbert Jaśniewicz (AlphaSOC) (SigmaHQ), DRL 1.1
- Published
- 2026-10-06
- Updated
- 2026-10-07
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script block text that enumerates Microsoft.PowerShell.Utility exported commands by using Get-Module/gmo with ListAvailable, ExportedCommands, and Values. It also requires evidence of array index usage patterns (ScriptBlockText containing [*]) to support indirect invocation. Such behavior can help attackers avoid detections that search for explicit cmdlet names by calling commands indirectly through an exported command list.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index"
id: 1092e474-39a6-46c4-bec5-8cc4d17a61d8
related:
- id: 0c3ebe9f-df09-4e00-be0f-73d4ca8d62f6
type: similar
- id: 4ff4ad3e-9fb5-4a70-9962-d6ea58090318
type: derived
status: experimental
description: This rule flags PowerShell script block text that enumerates Microsoft.PowerShell.Utility exported commands by using Get-Module/gmo with ListAvailable, ExportedCommands, and Values. It also requires evidence of array index usage patterns (ScriptBlockText containing [*]) to support indirect invocation. Such behavior can help attackers avoid detections that search for explicit cmdlet names by calling commands indirectly through an exported command list.
references:
- https://www.linkedin.com/posts/mark-o-halloran1_clickfix-defense-evasion-tactic-today-i-ugcPost-7453463467736408064-snrp/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_cmdlet_invocation_via_exported_commands_array_index.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2026-10-06
tags:
- attack.execution
- attack.stealth
- attack.t1027
- attack.t1059.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_module_export_enum:
ScriptBlockText|contains:
- "Get-Module "
- "gmo "
ScriptBlockText|contains|all:
- ListAvailable
- Microsoft.PowerShell.Utility
- ExportedCommands
- Values
selection_index_used:
ScriptBlockText|contains: "[*]"
condition: all of selection_*
falsepositives:
- Legitimate use of exported commands array indexing in PowerShell scripts (should be rare)
level: medium
regression_tests_path: regression_data/rules/windows/powershell/powershell_script/posh_ps_cmdlet_invocation_via_exported_commands_array_index/info.yml
license: DRL-1.1