Windows: CrackMapExec PowerShell obfuscation via join/split static patterns

Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Thomas Patzke (SigmaHQ), DRL 1.1
Published
2020-05-22
Updated
2026-07-31
title: "Windows: CrackMapExec PowerShell obfuscation via join/split static patterns"
id: e232e3ff-929d-4c57-ac0e-4dcaaed7a81d
status: test
description: This rule identifies PowerShell or pwsh process executions whose image paths and command-line content match static obfuscation patterns associated with CrackMapExec. Attackers may obfuscate PowerShell to hinder content inspection and signature-based detections. It relies on Windows process creation telemetry capturing the process image name/path and the full command line.
references:
  - https://github.com/byt3bl33d3r/CrackMapExec
  - https://github.com/byt3bl33d3r/CrackMapExec/blob/0a49f75347b625e81ee6aa8c33d3970b5515ea9e/cme/helpers/powershell.py#L242
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_powershell_obfuscation.yml
author: Thomas Patzke, Huntrule Team
date: 2020-05-22
modified: 2023-02-21
tags:
  - attack.execution
  - attack.stealth
  - attack.t1059.001
  - attack.t1027.005
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
  selection_cli:
    CommandLine|contains:
      - join*split
      - ( $ShellId[1]+$ShellId[13]+'x')
      - ( $PSHome[*]+$PSHOME[*]+
      - ( $env:Public[13]+$env:Public[5]+'x')
      - ( $env:ComSpec[4,*,25]-Join'')
      - "[1,3]+'x'-Join'')"
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 6f8b3439-a203-45dc-a88b-abf57ea15ccf
    type: derived