PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)

Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-08-24
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows process creation events where the command line includes the PowerShell base64 decoding pattern referencing FromBase64String. Attackers use FromBase64String to obfuscate commands and payloads, making content less readable in logs and aiding stealth. The detection relies on process command-line telemetry matching the FromBase64String marker and specific base64-encoded UTF-16 LE substrings.

Related detections9 linkedT1059.001 — drag to rearrange
Hidden PowerShell Archive Extraction via ExtractToDirectory
CastleLoader ClickFix PowerShell Hex Decode and Re-Execution
PowerShell Base64 Download Cradle via FromBase64String and Invoke-Expression (via ps_script)
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Suspicious Script Host Spawning Hidden PowerShell (via process_creation)
Suspicious PowerShell Reflective Assembly Load With GZip Decompression (via process_creation)
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.