Suspicious PowerShell Base64 Encoded Staged Downloader via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell executed with an encoded command combined with a hidden window and execution policy bypass which is typical of a staged malware downloader. TookPS used base64-encoded PowerShell stages to pull additional payloads before deploying the TeviRat and Lapmon backdoors. Encoded and hidden PowerShell invocations are a frequent early stage of intrusions and merit detection.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious PowerShell Version Pinning with Encoded Command
Suspicious Encoded PowerShell Spawned from Explorer via ClickFix
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
PowerShell ExportedCommands Array Index for Indirect Cmdlet Execution (Windows Process Creation)
Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index
Malicious Shadow Copy Deletion via WMI PowerShell
Malicious CACTUS Ransomware Deployment via TotalExec Script (via ps_script)
Suspicious PowerShell Base64 Encoded Staged Downloader via process_creation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.