Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice

Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-30
title: "Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice"
id: 689cde0a-8c82-4847-9a4e-9f25c61813e3
status: test
description: This rule identifies process executions where the PowerShell command line contains specific audio device cmdlet strings used for querying or modifying audio devices. Capturing or redirecting audio can support covert collection of user activity, making this activity important to investigate when unexpected. It relies on Windows process creation telemetry, specifically the command-line content used to launch PowerShell.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
  - https://eqllib.readthedocs.io/en/latest/analytics/ab7a6ef4-0983-4275-a4f1-5c6bd3c31c23.html
  - https://github.com/frgnca/AudioDeviceCmdlets
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-10-24
modified: 2023-04-06
tags:
  - attack.collection
  - attack.t1123
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - WindowsAudioDevice-Powershell-Cmdlet
      - Toggle-AudioDevice
      - "Get-AudioDevice "
      - "Set-AudioDevice "
      - "Write-AudioDevice "
  condition: selection
falsepositives:
  - Legitimate audio capture by legitimate user.
level: medium
license: DRL-1.1
related:
  - id: 932fb0d8-692b-4b0f-a26e-5643a50fe7d6
    type: derived