Suspicious PowerShell Module Execution Parameters for Encoded/Hidden Code
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
FreeUnreviewedSigmahighv1
suspicious-powershell-module-execution-parameters-for-encoded-hidden-code-8ff28fdd
title: Suspicious PowerShell Module Execution Parameters for Encoded/Hidden Code
id: df447db8-de97-4cfb-8744-f164d7e3550f
related:
- id: fce5f582-cc00-41e1-941a-c6fabf0fdb8c
type: obsolete
- id: ae7fbf8e-f3cb-49fd-8db4-5f3bed522c71
type: similar
- id: 536e2947-3729-478c-9903-745aaffe60d2
type: similar
- id: 8ff28fdd-e2fa-4dfa-aeda-ef3d61c62090
type: derived
status: test
description: This rule matches PowerShell module command lines that include hidden/windowless execution and encoded or base64/decode-and-execute patterns (for example, using FromBase64String, -Enc, or IEX/New-Object WebClient download-and-execute style). These invocation patterns are commonly used to run scripted payloads while reducing user visibility, and the module context helps focus on PowerShell-related activity. It relies on telemetry that captures PowerShell ContextInfo content for the presence of specific parameter and keyword combinations, and it excludes one known Chocolatey install snippet.
references:
- Internal Research
- https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_invocation_specific.yml
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule Team
date: 2017-03-05
modified: 2025-02-17
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_convert_b64:
ContextInfo|contains|all:
- -nop
- " -w "
- hidden
- " -c "
- "[Convert]::FromBase64String"
selection_iex:
ContextInfo|contains|all:
- " -w "
- hidden
- -noni
- -nop
- " -c "
- iex
- New-Object
selection_enc:
ContextInfo|contains|all:
- " -w "
- hidden
- -ep
- bypass
- -Enc
selection_reg:
ContextInfo|contains|all:
- powershell
- reg
- add
ContextInfo|contains:
- \software\microsoft\windows\currentversion\run
- \software\wow6432node\microsoft\windows\currentversion\run
- \software\microsoft\windows\currentversion\policies\explorer\run
selection_webclient:
ContextInfo|contains|all:
- bypass
- -noprofile
- -windowstyle
- hidden
- new-object
- system.net.webclient
- .download
selection_iex_webclient:
ContextInfo|contains|all:
- iex
- New-Object
- Net.WebClient
- .Download
filter_chocolatey:
ContextInfo|contains:
- (New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1
- Write-ChocolateyWarning
condition: 1 of selection_* and not 1 of filter_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule matches PowerShell module command lines that include hidden/windowless execution and encoded or base64/decode-and-execute patterns (for example, using FromBase64String, -Enc, or IEX/New-Object WebClient download-and-execute style). These invocation patterns are commonly used to run scripted payloads while reducing user visibility, and the module context helps focus on PowerShell-related activity. It relies on telemetry that captures PowerShell ContextInfo content for the presence of specific parameter and keyword combinations, and it excludes one known Chocolatey install snippet.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.