Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling

Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_module
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-20
Updated
2026-07-31

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows PowerShell module activity when the module payload contains commandlet names associated with well-known PowerShell exploitation and post-exploitation toolsets. Such behavior is commonly used by attackers to automate discovery, credential access, persistence, exfiltration, and privilege escalation via PowerShell. It relies on telemetry that includes the module payload content (Payload) where these commandlet strings appear.

Reporting behind it

Related detections9 linkedT1069.002 — drag to rearrange
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Windows file creation for SharpHound/BloodHound collection output filenames
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows Process Creation: Execution of Net.exe or Net1.exe
Suspicious Group Discovery - Command (via process_creation)
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Pivot detection · T1069.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.