PowerShell module: Obfuscated Invoke-Expression (IEX) payloads from Invoke-Obfuscation patterns

Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.

FreeUnreviewedSigmahighv1
title: "PowerShell module: Obfuscated Invoke-Expression (IEX) payloads from Invoke-Obfuscation patterns"
id: 44ac0c7b-a1d9-487f-8885-71ded80c6965
related:
  - id: 1b9dc62e-6e9e-42a3-8990-94d7a10007f7
    type: derived
  - id: 2f211361-7dce-442d-b78a-c04039677378
    type: derived
status: test
description: This rule flags PowerShell module activity where the script block payload matches multiple regular expressions associated with obfuscated Invoke-Expression (IEX) construction. Such obfuscation can hide the final command content and delay or evade straightforward detection during execution. It relies on telemetry that provides the module-level parsed payload content (captured in the Payload field) available for regex matching against these obfuscation indicators.
references:
  - https://github.com/danielbohannon/Invoke-Obfuscation/blob/f20e7f843edd0a3a7716736e9eddfa423395dd26/Out-ObfuscatedStringCommand.ps1#L873-L888
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_obfuscated_iex.yml
author: Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule Team
date: 2019-11-08
modified: 2022-12-31
tags:
  - attack.stealth
  - attack.t1027
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: ps_module
  definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
  selection_payload:
    - Payload|re: \$PSHome\[\s*\d{1,3}\s*\]\s*\+\s*\$PSHome\[
    - Payload|re: \$ShellId\[\s*\d{1,3}\s*\]\s*\+\s*\$ShellId\[
    - Payload|re: \$env:Public\[\s*\d{1,3}\s*\]\s*\+\s*\$env:Public\[
    - Payload|re: \$env:ComSpec\[(\s*\d{1,3}\s*,){2}
    - Payload|re: \*mdr\*\W\s*\)\.Name
    - Payload|re: \$VerbosePreference\.ToString\(
    - Payload|re: \[String\]\s*\$VerbosePreference
  condition: selection_payload
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags PowerShell module activity where the script block payload matches multiple regular expressions associated with obfuscated Invoke-Expression (IEX) construction. Such obfuscation can hide the final command content and delay or evade straightforward detection during execution. It relies on telemetry that provides the module-level parsed payload content (captured in the Payload field) available for regex matching against these obfuscation indicators.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.