Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
- Product
- windows
- Category
- process_creation
- Author
- E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2019-10-24
- Updated
- 2026-07-30
ATT&CK techniques
CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/ab7a6ef4-0983-4275-a4f1-5c6bd3c31c23.html
- github.comhttps://github.com/frgnca/AudioDeviceCmdlets
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice"
id: 689cde0a-8c82-4847-9a4e-9f25c61813e3
status: test
description: This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
- https://eqllib.readthedocs.io/en/latest/analytics/ab7a6ef4-0983-4275-a4f1-5c6bd3c31c23.html
- https://github.com/frgnca/AudioDeviceCmdlets
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-10-24
modified: 2023-04-06
tags:
- attack.collection
- attack.t1123
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- WindowsAudioDevice-Powershell-Cmdlet
- Toggle-AudioDevice
- "Get-AudioDevice "
- "Set-AudioDevice "
- "Write-AudioDevice "
condition: selection
falsepositives:
- Legitimate audio capture by legitimate user.
level: medium
license: DRL-1.1
related:
- id: 932fb0d8-692b-4b0f-a26e-5643a50fe7d6
type: derived