Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage

Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-04-02
Updated
2026-07-31
title: "Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage"
id: 78341c66-072a-4d96-8919-9618c181e3dd
status: test
description: This rule flags PowerShell script content that calls [System.Type]::GetTypeFromCLSID() and then invokes .ShellExecute(), a pattern commonly used to instantiate COM objects and execute actions from scripts. Attackers can use this technique to launch processes or trigger behaviors while leveraging COM activation and execution. The detection relies on script block text telemetry that captures the relevant code strings in logged PowerShell script content.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md#atomic-test-2---powershell-execute-com-object
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml
author: frack113, Huntrule Team
date: 2022-04-02
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1546.015
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains|all:
      - ::GetTypeFromCLSID(
      - .ShellExecute(
  condition: selection
falsepositives:
  - Legitimate PowerShell scripts
level: medium
license: DRL-1.1
related:
  - id: 8bc063d5-3a3a-4f01-a140-bc15e55e8437
    type: derived