Windows: Code execution via Pester.bat invoked by PowerShell (Invoke-Pester/Get-Help)

Alerts when PowerShell spawns Pester.bat with parent command lines referencing Pester invocation or help usage.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
frack113, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2022-08-20
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies process execution where the parent is Windows PowerShell (powershell.exe/pwsh.exe) and the parent command line references the Pester module path. It further matches parent commands that include common Pester usage patterns such as invoking Pester with exit enabled or calling Get-Help. This matters because attackers can leverage legitimate testing tooling to run PowerShell-driven code and blend into normal module activity. The rule relies on process creation telemetry capturing parent image and parent command line content.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious PowerShell Execution via SyncAppvPublishingServer LOLBIN
Malicious Command Injection via SyncAppvPublishingServer VBS LOLBin (via process_creation)
Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Suspicious PowerShell Spawned by cscript in Script Chain
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious PowerShell EncodedCommand Spawned From Command Shell via Process Creation
Suspicious Script Download via Curl and PowerShell by Dohdoor
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Windows: Code execution via Pester.bat invoked by PowerShell (Invoke-Pester/Get-Help)
Pivot detection · T1059.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.