Suspicious PowerShell Module Execution Parameters for Encoded/Hidden Code

Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.

FreeUnreviewedSigmahighv1
title: Suspicious PowerShell Module Execution Parameters for Encoded/Hidden Code
id: df447db8-de97-4cfb-8744-f164d7e3550f
related:
  - id: fce5f582-cc00-41e1-941a-c6fabf0fdb8c
    type: obsolete
  - id: ae7fbf8e-f3cb-49fd-8db4-5f3bed522c71
    type: similar
  - id: 536e2947-3729-478c-9903-745aaffe60d2
    type: similar
  - id: 8ff28fdd-e2fa-4dfa-aeda-ef3d61c62090
    type: derived
status: test
description: This rule matches PowerShell module command lines that include hidden/windowless execution and encoded or base64/decode-and-execute patterns (for example, using FromBase64String, -Enc, or IEX/New-Object WebClient download-and-execute style). These invocation patterns are commonly used to run scripted payloads while reducing user visibility, and the module context helps focus on PowerShell-related activity. It relies on telemetry that captures PowerShell ContextInfo content for the presence of specific parameter and keyword combinations, and it excludes one known Chocolatey install snippet.
references:
  - Internal Research
  - https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_invocation_specific.yml
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule Team
date: 2017-03-05
modified: 2025-02-17
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: ps_module
  definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
  selection_convert_b64:
    ContextInfo|contains|all:
      - -nop
      - " -w "
      - hidden
      - " -c "
      - "[Convert]::FromBase64String"
  selection_iex:
    ContextInfo|contains|all:
      - " -w "
      - hidden
      - -noni
      - -nop
      - " -c "
      - iex
      - New-Object
  selection_enc:
    ContextInfo|contains|all:
      - " -w "
      - hidden
      - -ep
      - bypass
      - -Enc
  selection_reg:
    ContextInfo|contains|all:
      - powershell
      - reg
      - add
    ContextInfo|contains:
      - \software\microsoft\windows\currentversion\run
      - \software\wow6432node\microsoft\windows\currentversion\run
      - \software\microsoft\windows\currentversion\policies\explorer\run
  selection_webclient:
    ContextInfo|contains|all:
      - bypass
      - -noprofile
      - -windowstyle
      - hidden
      - new-object
      - system.net.webclient
      - .download
  selection_iex_webclient:
    ContextInfo|contains|all:
      - iex
      - New-Object
      - Net.WebClient
      - .Download
  filter_chocolatey:
    ContextInfo|contains:
      - (New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1
      - Write-ChocolateyWarning
  condition: 1 of selection_* and not 1 of filter_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule matches PowerShell module command lines that include hidden/windowless execution and encoded or base64/decode-and-execute patterns (for example, using FromBase64String, -Enc, or IEX/New-Object WebClient download-and-execute style). These invocation patterns are commonly used to run scripted payloads while reducing user visibility, and the module context helps focus on PowerShell-related activity. It relies on telemetry that captures PowerShell ContextInfo content for the presence of specific parameter and keyword combinations, and it excludes one known Chocolatey install snippet.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.