Windows PowerShell: Invoke-Command targeting -ComputerName via script block
Detects PowerShell Invoke-Command targeting remote hosts by matching script block text with -ComputerName.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-01-07
- Updated
- 2026-07-31
ATT&CK techniques
Lateral MovementRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script block logging events containing an Invoke-Command call that includes the -ComputerName parameter targeting a remote host. Attackers can use this pattern to run commands on remote systems while leveraging existing valid user sessions for lateral movement. It relies on telemetry that records PowerShell script block text, specifically matching the presence of the Invoke-Command command and the remote computer argument.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.006/T1021.006.md#atomic-test-2---invoke-command
- learn.microsoft.comhttps://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/invoke-command?view=powershell-7.4
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_command_remote.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows PowerShell: Invoke-Command targeting -ComputerName via script block"
id: 4be3af98-e47d-436d-8ae8-d35190433737
status: test
description: This rule flags PowerShell script block logging events containing an Invoke-Command call that includes the -ComputerName parameter targeting a remote host. Attackers can use this pattern to run commands on remote systems while leveraging existing valid user sessions for lateral movement. It relies on telemetry that records PowerShell script block text, specifically matching the presence of the Invoke-Command command and the remote computer argument.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.006/T1021.006.md#atomic-test-2---invoke-command
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/invoke-command?view=powershell-7.4
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_command_remote.yml
author: frack113, Huntrule Team
date: 2022-01-07
tags:
- attack.lateral-movement
- attack.t1021.006
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_cmdlet:
ScriptBlockText|contains|all:
- "invoke-command "
- " -ComputerName "
condition: selection_cmdlet
falsepositives:
- Legitimate script
level: medium
license: DRL-1.1
related:
- id: 7b836d7f-179c-4ba4-90a7-a7e60afb48e6
type: derived