Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
- Product
- windows
- Category
- ps_module
- Author
- Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-07-13
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags creation of a PowerShell module where ModuleContents are set to define the function Get-VMRemoteFXPhysicalVideoAdapter. Attackers can use module creation to influence how a signed binary or related component loads PowerShell content, enabling module load-order manipulation. The detection relies on PowerShell module creation telemetry that includes the embedded ModuleContents text.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218/T1218.md
- github.comhttps://github.com/redcanaryco/AtomicTestHarnesses/blob/7e1e4da116801e3d6fcc6bedb207064577e40572/TestHarnesses/T1218_SignedBinaryProxyExecution/InvokeRemoteFXvGPUDisablementCommand.ps1
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_remotefxvgpudisablement_abuse.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
id: 7b3c101f-c694-44eb-b5e5-b361555030ee
related:
- id: a6fc3c46-23b8-4996-9ea2-573f4c4d88c5
type: similar
- id: f65e22f9-819e-4f96-9c7b-498364ae7a25
type: similar
- id: cacef8fc-9d3d-41f7-956d-455c6e881bc5
type: similar
- id: 38a7625e-b2cb-485d-b83d-aff137d859f4
type: derived
status: test
description: This rule flags creation of a PowerShell module where ModuleContents are set to define the function Get-VMRemoteFXPhysicalVideoAdapter. Attackers can use module creation to influence how a signed binary or related component loads PowerShell content, enabling module load-order manipulation. The detection relies on PowerShell module creation telemetry that includes the embedded ModuleContents text.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218/T1218.md
- https://github.com/redcanaryco/AtomicTestHarnesses/blob/7e1e4da116801e3d6fcc6bedb207064577e40572/TestHarnesses/T1218_SignedBinaryProxyExecution/InvokeRemoteFXvGPUDisablementCommand.ps1
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_remotefxvgpudisablement_abuse.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2021-07-13
modified: 2023-05-09
tags:
- attack.stealth
- attack.t1218
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection:
Payload|contains: ModuleContents=function Get-VMRemoteFXPhysicalVideoAdapter {
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1