Windows PowerShell: Invoke-Command for Remote Host Execution via Script Block Logging
Detects PowerShell Invoke-Command targeting remote hosts by matching script block text with -ComputerName.
FreeUnreviewedSigmamediumv1
windows-powershell-invoke-command-for-remote-host-execution-via-script-block-log-7b836d7f
title: "Windows PowerShell: Invoke-Command for Remote Host Execution via Script Block Logging"
id: 4be3af98-e47d-436d-8ae8-d35190433737
status: test
description: This rule flags PowerShell script blocks that contain both 'invoke-command ' and ' -ComputerName ', indicating use of Invoke-Command targeting a remote host. Attackers commonly leverage this pattern to run commands on other systems through authenticated remote execution channels. It relies on telemetry from PowerShell script block contents (Script Block Logging) to match the specified cmdlet and parameter text.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.006/T1021.006.md#atomic-test-2---invoke-command
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/invoke-command?view=powershell-7.4
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_command_remote.yml
author: frack113, Huntrule Team
date: 2022-01-07
tags:
- attack.lateral-movement
- attack.t1021.006
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_cmdlet:
ScriptBlockText|contains|all:
- "invoke-command "
- " -ComputerName "
condition: selection_cmdlet
falsepositives:
- Legitimate script
level: medium
license: DRL-1.1
related:
- id: 7b836d7f-179c-4ba4-90a7-a7e60afb48e6
type: derived
What it detects
This rule flags PowerShell script blocks that contain both 'invoke-command ' and ' -ComputerName ', indicating use of Invoke-Command targeting a remote host. Attackers commonly leverage this pattern to run commands on other systems through authenticated remote execution channels. It relies on telemetry from PowerShell script block contents (Script Block Logging) to match the specified cmdlet and parameter text.
Known false positives
- Legitimate script
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.