Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
- Product
- windows
- Category
- process_creation
- Author
- Moriarty Meng (idea), Anton Kutepov (rule), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-10-17
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies PowerShell or pwsh being launched with a command line containing a redirected input indicator ("- <"). Attackers can use redirected input to pass script content or commands through the process invocation, helping execution blend into less obvious command-line patterns. Detection relies on Windows process creation telemetry capturing the PowerShell executable path and the full command line.
Reporting behind it
- github.comhttps://github.com/LOLBAS-Project/LOLBAS/blob/4db780e0f0b2e2bb8cb1fa13e09196da9b9f1834/yml/LOLUtilz/OSBinaries/Powershell.yml
- twitter.comhttps://twitter.com/Moriarty_Meng/status/984380793383370752
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_run_script_from_input_stream.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows PowerShell Script Execution via Redirected Input Stream
id: 12e50a99-c99c-439d-9a94-db9bebf8f19c
status: test
description: This rule identifies PowerShell or pwsh being launched with a command line containing a redirected input indicator ("- <"). Attackers can use redirected input to pass script content or commands through the process invocation, helping execution blend into less obvious command-line patterns. Detection relies on Windows process creation telemetry capturing the PowerShell executable path and the full command line.
references:
- https://github.com/LOLBAS-Project/LOLBAS/blob/4db780e0f0b2e2bb8cb1fa13e09196da9b9f1834/yml/LOLUtilz/OSBinaries/Powershell.yml
- https://twitter.com/Moriarty_Meng/status/984380793383370752
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_run_script_from_input_stream.yml
author: Moriarty Meng (idea), Anton Kutepov (rule), oscd.community, Huntrule Team
date: 2020-10-17
modified: 2021-11-27
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- \powershell.exe
- \pwsh.exe
CommandLine|re: \s-\s*<
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: c83bf4b5-cdf0-437c-90fa-43d734f7c476
type: derived