Windows PowerShell: GetTypeFromCLSID ShellExecute Usage

Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.

FreeUnreviewedSigmamediumv1
title: "Windows PowerShell: GetTypeFromCLSID ShellExecute Usage"
id: 78341c66-072a-4d96-8919-9618c181e3dd
status: test
description: This rule identifies PowerShell script content that constructs a COM type using ::GetTypeFromCLSID(...) and then invokes .ShellExecute(...). Attackers may use COM activation to launch commands or persist by abusing object creation and execution pathways from PowerShell. The detection relies on script block text telemetry and matches the specific string patterns present in the logged script content.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md#atomic-test-2---powershell-execute-com-object
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml
author: frack113, Huntrule Team
date: 2022-04-02
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1546.015
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains|all:
      - ::GetTypeFromCLSID(
      - .ShellExecute(
  condition: selection
falsepositives:
  - Legitimate PowerShell scripts
level: medium
license: DRL-1.1
related:
  - id: 8bc063d5-3a3a-4f01-a140-bc15e55e8437
    type: derived

What it detects

This rule identifies PowerShell script content that constructs a COM type using ::GetTypeFromCLSID(...) and then invokes .ShellExecute(...). Attackers may use COM activation to launch commands or persist by abusing object creation and execution pathways from PowerShell. The detection relies on script block text telemetry and matches the specific string patterns present in the logged script content.

Known false positives

  • Legitimate PowerShell scripts

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.