Windows PowerShell script uses Invoke-WebRequest with POST or PUT to upload data
PowerShell scripts referencing Invoke-WebRequest with -Method POST/PUT indicate potential data upload behavior.
FreeUnreviewedSigmalowv1
windows-powershell-script-uses-invoke-webrequest-with-post-or-put-to-upload-data-d2e3f2f6
title: Windows PowerShell script uses Invoke-WebRequest with POST or PUT to upload data
id: cab463e3-49b0-4fe2-aa8d-606e2b4e8559
status: test
description: This rule flags PowerShell script blocks that include Invoke-WebRequest (or related aliases like iwr/irm) together with explicit HTTP upload methods of POST or PUT. Attackers commonly use this pattern to exfiltrate or move data by sending it to external endpoints over HTTP using the script’s built-in web request capabilities. It relies on Windows PowerShell script block text telemetry to match the presence of the cmdlet and the specified -Method values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1020/T1020.md
- https://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-7.4
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_script_with_upload_capabilities.yml
author: frack113, Huntrule Team
date: 2022-01-07
modified: 2025-07-18
tags:
- attack.exfiltration
- attack.t1020
logsource:
product: windows
category: ps_script
definition: bade5735-5ab0-4aa7-a642-a11be0e40872
detection:
selection_cmdlet:
ScriptBlockText|contains:
- Invoke-RestMethod
- Invoke-WebRequest
- "irm "
- "iwr "
selection_flag:
ScriptBlockText|contains:
- -Method "POST"
- -Method "PUT"
- -Method POST
- -Method PUT
- -Method 'POST'
- -Method 'PUT'
condition: all of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1
related:
- id: d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
type: derived
What it detects
This rule flags PowerShell script blocks that include Invoke-WebRequest (or related aliases like iwr/irm) together with explicit HTTP upload methods of POST or PUT. Attackers commonly use this pattern to exfiltrate or move data by sending it to external endpoints over HTTP using the script’s built-in web request capabilities. It relies on Windows PowerShell script block text telemetry to match the presence of the cmdlet and the specified -Method values.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.