Windows PowerShell Script Block Alerts for Common Credential Theft and Memory Injection Keywords

Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.

FreeUnreviewedSigmamediumv1
title: Windows PowerShell Script Block Alerts for Common Credential Theft and Memory Injection Keywords
id: 8801e92f-6a71-45b7-840d-23eb3b96ebcb
status: test
description: This rule flags PowerShell script block content containing strings associated with process memory access, token privilege manipulation, and in-memory/offensive tooling usage. Attackers often embed these keywords in scripts to interact with Windows APIs for credential theft, privilege escalation, or memory dumping. It relies on Windows PowerShell script block logging telemetry and matches against the presence of specific keyword substrings within ScriptBlockText.
references:
  - https://adsecurity.org/?p=2921
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_malicious_keywords.yml
author: Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-05
modified: 2023-06-20
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains:
      - AdjustTokenPrivileges
      - IMAGE_NT_OPTIONAL_HDR64_MAGIC
      - Metasploit
      - Microsoft.Win32.UnsafeNativeMethods
      - Mimikatz
      - MiniDumpWriteDump
      - PAGE_EXECUTE_READ
      - ReadProcessMemory.Invoke
      - SE_PRIVILEGE_ENABLED
      - SECURITY_DELEGATION
      - TOKEN_ADJUST_PRIVILEGES
      - TOKEN_ALL_ACCESS
      - TOKEN_ASSIGN_PRIMARY
      - TOKEN_DUPLICATE
      - TOKEN_ELEVATION
      - TOKEN_IMPERSONATE
      - TOKEN_INFORMATION_CLASS
      - TOKEN_PRIVILEGES
      - TOKEN_QUERY
  condition: selection
falsepositives:
  - Depending on the scripts, this rule might require some initial tuning to fit the environment
level: medium
license: DRL-1.1
related:
  - id: f62176f3-8128-4faa-bf6c-83261322e5eb
    type: derived

What it detects

This rule flags PowerShell script block content containing strings associated with process memory access, token privilege manipulation, and in-memory/offensive tooling usage. Attackers often embed these keywords in scripts to interact with Windows APIs for credential theft, privilege escalation, or memory dumping. It relies on Windows PowerShell script block logging telemetry and matches against the presence of specific keyword substrings within ScriptBlockText.

Known false positives

  • Depending on the scripts, this rule might require some initial tuning to fit the environment

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.