Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
- Product
- windows
- Category
- ps_script
- Author
- Sean Metcalf (source), Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-03-05
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script block content that includes specific strings commonly used by exploitation and post-exploitation tooling. Attackers rely on these APIs, memory operations, and token manipulation patterns to elevate privileges, access sensitive process memory, or execute actions associated with credential theft. Detection depends on Script Block Logging telemetry that records the PowerShell script block text for keyword matching.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
id: 8801e92f-6a71-45b7-840d-23eb3b96ebcb
status: test
description: This rule flags PowerShell script block content that includes specific strings commonly used by exploitation and post-exploitation tooling. Attackers rely on these APIs, memory operations, and token manipulation patterns to elevate privileges, access sensitive process memory, or execute actions associated with credential theft. Detection depends on Script Block Logging telemetry that records the PowerShell script block text for keyword matching.
references:
- https://adsecurity.org/?p=2921
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_malicious_keywords.yml
author: Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-05
modified: 2023-06-20
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains:
- AdjustTokenPrivileges
- IMAGE_NT_OPTIONAL_HDR64_MAGIC
- Metasploit
- Microsoft.Win32.UnsafeNativeMethods
- Mimikatz
- MiniDumpWriteDump
- PAGE_EXECUTE_READ
- ReadProcessMemory.Invoke
- SE_PRIVILEGE_ENABLED
- SECURITY_DELEGATION
- TOKEN_ADJUST_PRIVILEGES
- TOKEN_ALL_ACCESS
- TOKEN_ASSIGN_PRIMARY
- TOKEN_DUPLICATE
- TOKEN_ELEVATION
- TOKEN_IMPERSONATE
- TOKEN_INFORMATION_CLASS
- TOKEN_PRIVILEGES
- TOKEN_QUERY
condition: selection
falsepositives:
- Depending on the scripts, this rule might require some initial tuning to fit the environment
level: medium
license: DRL-1.1
related:
- id: f62176f3-8128-4faa-bf6c-83261322e5eb
type: derived