PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)

Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113, Tim Shelton (fp AWS) (SigmaHQ), DRL 1.1
Published
2021-10-20
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags PowerShell script block content that includes the terms "powershell", "WindowStyle", and "Hidden", which can indicate an attempt to run with a concealed window. Attackers may use hidden windows to reduce user visibility while executing actions on a host. The detection relies on Script Block Logging telemetry and matches on ScriptBlockText substring content, excluding matches that contain specific Amazon WorkSpaces-related script paths.

Related detections9 linkedT1564.003 — drag to rearrange
Suspicious Script Host Spawning Hidden PowerShell (via process_creation)
Conhost Suspicious Command Execution
Suspicious conhost Headless Execution for Hidden Window
Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
PowerShell Launch With --headless From Conhost.exe on Windows
Windows: Headless Chromium Browser Execution via --headless
Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Windows PUA AdvancedRun.exe Execution
Windows Process Creation: Headless Chromium Download via dump-dom
PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Pivot detection · T1564.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.