PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns
Alerts on obfuscated PowerShell IEX invocation strings built from Invoke-Obfuscation style concatenation patterns in ScriptBlockText.
- Product
- windows
- Category
- ps_script
- Author
- Daniel Bohannon (@Mandiant/@FireEye), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-11-08
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script block content that matches characteristic patterns used to obfuscate variables and strings in an IEX (Invoke-Expression) invocation. Attackers rely on obfuscation to evade inspection while still executing dynamically constructed code. The detection depends on Script Block Logging telemetry that captures ScriptBlockText for matching regular expressions.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns"
id: 42ab965e-b209-450d-88e5-9a1c8e0c0f85
status: test
description: This rule flags PowerShell script block content that matches characteristic patterns used to obfuscate variables and strings in an IEX (Invoke-Expression) invocation. Attackers rely on obfuscation to evade inspection while still executing dynamically constructed code. The detection depends on Script Block Logging telemetry that captures ScriptBlockText for matching regular expressions.
references:
- https://github.com/danielbohannon/Invoke-Obfuscation/blob/f20e7f843edd0a3a7716736e9eddfa423395dd26/Out-ObfuscatedStringCommand.ps1#L873-L888
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_obfuscated_iex.yml
author: Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule Team
date: 2019-11-08
modified: 2022-12-31
tags:
- attack.stealth
- attack.t1027
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_iex:
- ScriptBlockText|re: \$PSHome\[\s*\d{1,3}\s*\]\s*\+\s*\$PSHome\[
- ScriptBlockText|re: \$ShellId\[\s*\d{1,3}\s*\]\s*\+\s*\$ShellId\[
- ScriptBlockText|re: \$env:Public\[\s*\d{1,3}\s*\]\s*\+\s*\$env:Public\[
- ScriptBlockText|re: \$env:ComSpec\[(\s*\d{1,3}\s*,){2}
- ScriptBlockText|re: \*mdr\*\W\s*\)\.Name
- ScriptBlockText|re: \$VerbosePreference\.ToString\(
condition: selection_iex
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 1b9dc62e-6e9e-42a3-8990-94d7a10007f7
type: derived