PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
FreeUnreviewedSigmamediumv1
powershell-spawned-by-wscript-exe-or-cscript-exe-on-windows-95eadcb2
title: PowerShell Spawned by wscript.exe or cscript.exe on Windows
id: d820a2f6-cee7-46ac-a322-6613eeff37f2
status: test
description: This rule identifies PowerShell executions where the parent process is wscript.exe or cscript.exe and the child process is powershell.exe or pwsh.exe. Attackers often use script engines to launch PowerShell for execution and staging while blending into common automation workflows. The detection relies on Windows process creation telemetry capturing parent and image paths, with an exclusion for processes with a current directory containing '\Health Service State\'.
references:
- https://www.securitynewspaper.com/2017/03/20/attackers-leverage-excel-powershell-dns-latest-non-malware-attack/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_script_engine_parent.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2019-01-16
modified: 2023-01-05
tags:
- attack.execution
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- \wscript.exe
- \cscript.exe
Image|endswith:
- \powershell.exe
- \pwsh.exe
filter_health_service:
CurrentDirectory|contains: \Health Service State\
condition: selection and not 1 of filter_*
falsepositives:
- Microsoft Operations Manager (MOM)
- Other scripts
level: medium
license: DRL-1.1
related:
- id: 95eadcb2-92e4-4ed1-9031-92547773a6db
type: derived
What it detects
This rule identifies PowerShell executions where the parent process is wscript.exe or cscript.exe and the child process is powershell.exe or pwsh.exe. Attackers often use script engines to launch PowerShell for execution and staging while blending into common automation workflows. The detection relies on Windows process creation telemetry capturing parent and image paths, with an exclusion for processes with a current directory containing '\Health Service State\'.
Known false positives
- Microsoft Operations Manager (MOM)
- Other scripts
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.