Windows Capability Installation via PowerShell Add-WindowsCapability Script Blocks

Flags PowerShell commands that add Windows capabilities, specifically OpenSSH, via Add-WindowsCapability in logged script blocks.

FreeUnreviewedSigmamediumv1
title: Windows Capability Installation via PowerShell Add-WindowsCapability Script Blocks
id: df8bb8ca-0408-4fda-b762-03c4cbc0e1fe
related:
  - id: b36d01a3-ddaf-4804-be18-18a6247adfcd
    type: similar
  - id: 155c7fd5-47b4-49b2-bbeb-eb4fab335429
    type: derived
status: test
description: This rule identifies PowerShell script block content that invokes the Add-WindowsCapability cmdlet with the OpenSSH capability specified. Attackers may use this to quickly install additional Windows features or services to expand access or enable remote connectivity. Telemetry required is PowerShell Script Block Logging, since the match is based on the ScriptBlockText content containing the cmdlet and capability parameters.
references:
  - https://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse?tabs=powershell
  - https://www.virustotal.com/gui/file/af1c82237b6e5a3a7cdbad82cc498d298c67845d92971bada450023d1335e267/content
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_add_windows_capability.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-22
modified: 2023-05-09
tags:
  - attack.execution
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_cmdlet:
    ScriptBlockText|contains: "Add-WindowsCapability "
  selection_capa:
    ScriptBlockText|contains: -Name OpenSSH.
  condition: all of selection_*
falsepositives:
  - Legitimate usage of the capabilities by administrators or users. Add additional filters accordingly.
level: medium
license: DRL-1.1

What it detects

This rule identifies PowerShell script block content that invokes the Add-WindowsCapability cmdlet with the OpenSSH capability specified. Attackers may use this to quickly install additional Windows features or services to expand access or enable remote connectivity. Telemetry required is PowerShell Script Block Logging, since the match is based on the ScriptBlockText content containing the cmdlet and capability parameters.

Known false positives

  • Legitimate usage of the capabilities by administrators or users. Add additional filters accordingly.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.