Suspicious Encoded PowerShell Execution with No Profile

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-18
Updated
2026-09-18

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell launched with the -noprofile flag alongside an encoded command argument, the launcher pattern seen delivering the FORMBOOK payload dllhostSvc.exe. Combining profile suppression with base64-encoded commands is a common obfuscation used to hide the downloaded second stage.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Remote Thread Creation via rundll32 Triggered by wab*, wabmig, or ImagingDevices
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Suspicious PowerShell Encoded Command Execution
Malicious WARMCOOKIE Loader Execution via rundll32 RtlUpd via process_creation
Suspicious PowerShell BITS Transfer of DLL Payload via process_creation
Malicious Masquerading TiWorker Spawning PowerShell Downloader via process_creation
Suspicious Script Host Spawning PowerShell via Process Creation
Suspicious Encoded PowerShell Execution with No Profile
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.