Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage
Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-04-02
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script content that calls [System.Type]::GetTypeFromCLSID() and then invokes .ShellExecute(), a pattern commonly used to instantiate COM objects and execute actions from scripts. Attackers can use this technique to launch processes or trigger behaviors while leveraging COM activation and execution. The detection relies on script block text telemetry that captures the relevant code strings in logged PowerShell script content.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md#atomic-test-2---powershell-execute-com-object
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage"
id: 78341c66-072a-4d96-8919-9618c181e3dd
status: test
description: This rule flags PowerShell script content that calls [System.Type]::GetTypeFromCLSID() and then invokes .ShellExecute(), a pattern commonly used to instantiate COM objects and execute actions from scripts. Attackers can use this technique to launch processes or trigger behaviors while leveraging COM activation and execution. The detection relies on script block text telemetry that captures the relevant code strings in logged PowerShell script content.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md#atomic-test-2---powershell-execute-com-object
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml
author: frack113, Huntrule Team
date: 2022-04-02
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.015
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains|all:
- ::GetTypeFromCLSID(
- .ShellExecute(
condition: selection
falsepositives:
- Legitimate PowerShell scripts
level: medium
license: DRL-1.1
related:
- id: 8bc063d5-3a3a-4f01-a140-bc15e55e8437
type: derived