Windows PowerShell Script Block Alerts for Common Credential Theft and Memory Injection Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
FreeUnreviewedSigmamediumv1
windows-powershell-script-block-alerts-for-common-credential-theft-and-memory-in-f62176f3
title: Windows PowerShell Script Block Alerts for Common Credential Theft and Memory Injection Keywords
id: 8801e92f-6a71-45b7-840d-23eb3b96ebcb
status: test
description: This rule flags PowerShell script block content containing strings associated with process memory access, token privilege manipulation, and in-memory/offensive tooling usage. Attackers often embed these keywords in scripts to interact with Windows APIs for credential theft, privilege escalation, or memory dumping. It relies on Windows PowerShell script block logging telemetry and matches against the presence of specific keyword substrings within ScriptBlockText.
references:
- https://adsecurity.org/?p=2921
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_malicious_keywords.yml
author: Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-05
modified: 2023-06-20
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains:
- AdjustTokenPrivileges
- IMAGE_NT_OPTIONAL_HDR64_MAGIC
- Metasploit
- Microsoft.Win32.UnsafeNativeMethods
- Mimikatz
- MiniDumpWriteDump
- PAGE_EXECUTE_READ
- ReadProcessMemory.Invoke
- SE_PRIVILEGE_ENABLED
- SECURITY_DELEGATION
- TOKEN_ADJUST_PRIVILEGES
- TOKEN_ALL_ACCESS
- TOKEN_ASSIGN_PRIMARY
- TOKEN_DUPLICATE
- TOKEN_ELEVATION
- TOKEN_IMPERSONATE
- TOKEN_INFORMATION_CLASS
- TOKEN_PRIVILEGES
- TOKEN_QUERY
condition: selection
falsepositives:
- Depending on the scripts, this rule might require some initial tuning to fit the environment
level: medium
license: DRL-1.1
related:
- id: f62176f3-8128-4faa-bf6c-83261322e5eb
type: derived
What it detects
This rule flags PowerShell script block content containing strings associated with process memory access, token privilege manipulation, and in-memory/offensive tooling usage. Attackers often embed these keywords in scripts to interact with Windows APIs for credential theft, privilege escalation, or memory dumping. It relies on Windows PowerShell script block logging telemetry and matches against the presence of specific keyword substrings within ScriptBlockText.
Known false positives
- Depending on the scripts, this rule might require some initial tuning to fit the environment
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.