Suspicious PowerShell Script Block Invocations Using Encoded/Hidden Execution and Persistence Commands

Flags PowerShell script blocks using hidden/non-interactive execution, encoded/decode patterns, iex execution, web downloads, or run key modifications.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_script
Author
Florian Roth (Nextron Systems), Jonhnathan Ribeiro (SigmaHQ), DRL 1.1
Published
2017-03-05
Updated
2026-07-31
title: Suspicious PowerShell Script Block Invocations Using Encoded/Hidden Execution and Persistence Commands
id: 3f37ccd6-a0fb-4fc3-bc01-33c3d86a0a31
related:
  - id: fce5f582-cc00-41e1-941a-c6fabf0fdb8c
    type: obsolete
  - id: 8ff28fdd-e2fa-4dfa-aeda-ef3d61c62090
    type: similar
  - id: 536e2947-3729-478c-9903-745aaffe60d2
    type: similar
  - id: ae7fbf8e-f3cb-49fd-8db4-5f3bed522c71
    type: derived
status: test
description: This rule flags PowerShell script block content that includes execution patterns commonly used to run code covertly, such as hidden windows, execution policy bypass, encoded payload handling, and base64-to-bytes decoding with Convert.FromBase64String. It also matches script blocks that combine web download techniques with iex/New-Object usage and those that attempt to establish persistence by modifying common Run registry keys. The detection relies on Script Block Logging telemetry (ScriptBlockText) to match specific parameter and command substrings within PowerShell activity.
references:
  - Internal Research
  - https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_invocation_specific.yml
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule Team
date: 2017-03-05
modified: 2025-02-17
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_convert_b64:
    ScriptBlockText|contains|all:
      - -nop
      - " -w "
      - hidden
      - " -c "
      - "[Convert]::FromBase64String"
  selection_iex_selection:
    ScriptBlockText|contains|all:
      - " -w "
      - hidden
      - -noni
      - -nop
      - " -c "
      - iex
      - New-Object
  selection_enc_selection:
    ScriptBlockText|contains|all:
      - " -w "
      - hidden
      - -ep
      - bypass
      - -Enc
  selection_reg_selection:
    ScriptBlockText|contains|all:
      - powershell
      - reg
      - add
    ScriptBlockText|contains:
      - \software\microsoft\windows\currentversion\run
      - \software\wow6432node\microsoft\windows\currentversion\run
      - \software\microsoft\windows\currentversion\policies\explorer\run
  selection_webclient_selection:
    ScriptBlockText|contains|all:
      - bypass
      - -noprofile
      - -windowstyle
      - hidden
      - new-object
      - system.net.webclient
      - .download
  selection_iex_webclient:
    ScriptBlockText|contains|all:
      - iex
      - New-Object
      - Net.WebClient
      - .Download
  filter_chocolatey:
    ScriptBlockText|contains:
      - (New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1
      - (New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1')
      - Write-ChocolateyWarning
  condition: 1 of selection_* and not 1 of filter_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1