PowerShell module: Obfuscated Invoke-Expression (IEX) payloads from Invoke-Obfuscation patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
FreeUnreviewedSigmahighv1
powershell-module-obfuscated-invoke-expression-iex-payloads-from-invoke-obfuscat-2f211361
title: "PowerShell module: Obfuscated Invoke-Expression (IEX) payloads from Invoke-Obfuscation patterns"
id: 44ac0c7b-a1d9-487f-8885-71ded80c6965
related:
- id: 1b9dc62e-6e9e-42a3-8990-94d7a10007f7
type: derived
- id: 2f211361-7dce-442d-b78a-c04039677378
type: derived
status: test
description: This rule flags PowerShell module activity where the script block payload matches multiple regular expressions associated with obfuscated Invoke-Expression (IEX) construction. Such obfuscation can hide the final command content and delay or evade straightforward detection during execution. It relies on telemetry that provides the module-level parsed payload content (captured in the Payload field) available for regex matching against these obfuscation indicators.
references:
- https://github.com/danielbohannon/Invoke-Obfuscation/blob/f20e7f843edd0a3a7716736e9eddfa423395dd26/Out-ObfuscatedStringCommand.ps1#L873-L888
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_obfuscated_iex.yml
author: Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule Team
date: 2019-11-08
modified: 2022-12-31
tags:
- attack.stealth
- attack.t1027
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_payload:
- Payload|re: \$PSHome\[\s*\d{1,3}\s*\]\s*\+\s*\$PSHome\[
- Payload|re: \$ShellId\[\s*\d{1,3}\s*\]\s*\+\s*\$ShellId\[
- Payload|re: \$env:Public\[\s*\d{1,3}\s*\]\s*\+\s*\$env:Public\[
- Payload|re: \$env:ComSpec\[(\s*\d{1,3}\s*,){2}
- Payload|re: \*mdr\*\W\s*\)\.Name
- Payload|re: \$VerbosePreference\.ToString\(
- Payload|re: \[String\]\s*\$VerbosePreference
condition: selection_payload
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags PowerShell module activity where the script block payload matches multiple regular expressions associated with obfuscated Invoke-Expression (IEX) construction. Such obfuscation can hide the final command content and delay or evade straightforward detection during execution. It relies on telemetry that provides the module-level parsed payload content (captured in the Payload field) available for regex matching against these obfuscation indicators.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.