Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice

Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.

FreeUnreviewedSigmamediumv1
title: "Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice"
id: 689cde0a-8c82-4847-9a4e-9f25c61813e3
status: test
description: This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
  - https://eqllib.readthedocs.io/en/latest/analytics/ab7a6ef4-0983-4275-a4f1-5c6bd3c31c23.html
  - https://github.com/frgnca/AudioDeviceCmdlets
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-10-24
modified: 2023-04-06
tags:
  - attack.collection
  - attack.t1123
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - WindowsAudioDevice-Powershell-Cmdlet
      - Toggle-AudioDevice
      - "Get-AudioDevice "
      - "Set-AudioDevice "
      - "Write-AudioDevice "
  condition: selection
falsepositives:
  - Legitimate audio capture by legitimate user.
level: medium
license: DRL-1.1
related:
  - id: 932fb0d8-692b-4b0f-a26e-5643a50fe7d6
    type: derived

What it detects

This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.

Known false positives

  • Legitimate audio capture by legitimate user.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.