Windows PowerShell process command lines with Empire-style encoded/persistence launch parameters

Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.

FreeUnreviewedSigmahighv1
title: Windows PowerShell process command lines with Empire-style encoded/persistence launch parameters
id: be1aef67-b12b-41be-9e8b-01ec1271dc28
status: test
description: This rule matches Windows process creation events where the PowerShell command line contains Empire-like parameters for hidden execution and encoded payload delivery (including -EncodedCommand variants). Attackers commonly use encoded and stealth-oriented PowerShell parameters to reduce visibility and to stage or execute malicious scripts through PowerShell. Telemetry required includes process creation details, specifically the full CommandLine field for PowerShell executions.
references:
  - https://github.com/EmpireProject/Empire/blob/c2ba61ca8d2031dad0cfc1d5770ba723e8b710db/lib/common/helpers.py#L165
  - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/deaduser.py#L191
  - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/lib/modules/powershell/persistence/powerbreach/resolver.py#L178
  - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_empire_powershell_launch.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2019-04-20
modified: 2023-02-21
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - " -NoP -sta -NonI -W Hidden -Enc "
      - " -noP -sta -w 1 -enc "
      - " -NoP -NonI -W Hidden -enc "
      - " -noP -sta -w 1 -enc"
      - " -enc  SQB"
      - " -nop -exec bypass -EncodedCommand "
  condition: selection
falsepositives:
  - Other tools that incidentally use the same command line parameters
level: high
license: DRL-1.1
related:
  - id: 79f4ede3-402e-41c8-bc3e-ebbf5f162581
    type: derived

What it detects

This rule matches Windows process creation events where the PowerShell command line contains Empire-like parameters for hidden execution and encoded payload delivery (including -EncodedCommand variants). Attackers commonly use encoded and stealth-oriented PowerShell parameters to reduce visibility and to stage or execute malicious scripts through PowerShell. Telemetry required includes process creation details, specifically the full CommandLine field for PowerShell executions.

Known false positives

  • Other tools that incidentally use the same command line parameters

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.