Windows Capability Added via PowerShell Add-WindowsCapability (OpenSSH)
Flags PowerShell commands that add Windows capabilities, specifically OpenSSH, via Add-WindowsCapability in logged script blocks.
FreeReviewedSigma · Medium · v2
- Product
- windows
- Category
- ps_script
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-01-22
- Updated
- 2026-07-31
What it detects
This rule identifies PowerShell script content that invokes the Add-WindowsCapability cmdlet with the -Name OpenSSH. Adding Windows capabilities can expand functionality on a system and may be leveraged by attackers to enable additional components such as remote access features. The detection relies on PowerShell Script Block logging telemetry capturing the ScriptBlockText that contains the cmdlet call and the specified capability name.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse?tabs=powershell
- virustotal.comhttps://www.virustotal.com/gui/file/af1c82237b6e5a3a7cdbad82cc498d298c67845d92971bada450023d1335e267/content
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_add_windows_capability.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-capability-installation-via-powershell-add-windowscapability-script-bloc-155c7fd5
title: Windows Capability Added via PowerShell Add-WindowsCapability (OpenSSH)
id: df8bb8ca-0408-4fda-b762-03c4cbc0e1fe
related:
- id: b36d01a3-ddaf-4804-be18-18a6247adfcd
type: similar
- id: 155c7fd5-47b4-49b2-bbeb-eb4fab335429
type: derived
status: test
description: This rule identifies PowerShell script content that invokes the Add-WindowsCapability cmdlet with the -Name OpenSSH. Adding Windows capabilities can expand functionality on a system and may be leveraged by attackers to enable additional components such as remote access features. The detection relies on PowerShell Script Block logging telemetry capturing the ScriptBlockText that contains the cmdlet call and the specified capability name.
references:
- https://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse?tabs=powershell
- https://www.virustotal.com/gui/file/af1c82237b6e5a3a7cdbad82cc498d298c67845d92971bada450023d1335e267/content
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_add_windows_capability.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-22
modified: 2023-05-09
tags:
- attack.execution
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_cmdlet:
ScriptBlockText|contains: "Add-WindowsCapability "
selection_capa:
ScriptBlockText|contains: -Name OpenSSH.
condition: all of selection_*
falsepositives:
- Legitimate usage of the capabilities by administrators or users. Add additional filters accordingly.
level: medium
license: DRL-1.1