Suspicious PowerShell Spawned by WScript With Hidden Bypass via PureLogs Loader (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the PureLogs phishing chain in which a malicious JavaScript file executed by wscript.exe spawns PowerShell with an execution policy bypass and a hidden window to run a dropped script from a temp folder. This parent child relationship between the script host and PowerShell is a strong loader signal. The staged script then hollows a .NET binary.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious PowerShell Execution of TrainedDataStore Script
Suspicious Archive Expansion into Public User Directory via PowerShell (via ps_script)
Suspicious ClickFix PowerShell Download Cradle via TAG-150 Tradecraft
Malicious PowerShell Download of FortiEndpoint Patch Masquerade via EKZ Stealer
Suspicious Delayed Expansion Command Obfuscation Building PowerShell via Amatera Stealer
Suspicious PowerShell Host and Locale Reconnaissance via MuddyWater Tsundere Botnet
Malicious PowerShell StreamReader WebRequest Download Cradle
Suspicious PowerShell UTF8 OutputEncoding Command Wrapper
Malicious PowerShell Clipboard Script Execution via ScriptBlock Create
Suspicious PowerShell Spawned by WScript With Hidden Bypass via PureLogs Loader (via process_creation)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.