Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice

Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.

Related detections5 linkedT1123 — drag to rearrange
OpenCanary SIP Request on Honeypot Node
Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Windows Process Creation: SoundRecorder audio capture using /FILE
Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Pivot detection · T1123 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.