Windows PowerShell: Invoke-Command targeting -ComputerName via script block

Detects PowerShell Invoke-Command targeting remote hosts by matching script block text with -ComputerName.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-07
Updated
2026-07-31
title: "Windows PowerShell: Invoke-Command targeting -ComputerName via script block"
id: 4be3af98-e47d-436d-8ae8-d35190433737
status: test
description: This rule flags PowerShell script block logging events containing an Invoke-Command call that includes the -ComputerName parameter targeting a remote host. Attackers can use this pattern to run commands on remote systems while leveraging existing valid user sessions for lateral movement. It relies on telemetry that records PowerShell script block text, specifically matching the presence of the Invoke-Command command and the remote computer argument.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.006/T1021.006.md#atomic-test-2---invoke-command
  - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/invoke-command?view=powershell-7.4
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_command_remote.yml
author: frack113, Huntrule Team
date: 2022-01-07
tags:
  - attack.lateral-movement
  - attack.t1021.006
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_cmdlet:
    ScriptBlockText|contains|all:
      - "invoke-command "
      - " -ComputerName "
  condition: selection_cmdlet
falsepositives:
  - Legitimate script
level: medium
license: DRL-1.1
related:
  - id: 7b836d7f-179c-4ba4-90a7-a7e60afb48e6
    type: derived