Windows PowerShell script uses Invoke-WebRequest with POST or PUT to upload data

PowerShell scripts referencing Invoke-WebRequest with -Method POST/PUT indicate potential data upload behavior.

FreeUnreviewedSigmalowv1
title: Windows PowerShell script uses Invoke-WebRequest with POST or PUT to upload data
id: cab463e3-49b0-4fe2-aa8d-606e2b4e8559
status: test
description: This rule flags PowerShell script blocks that include Invoke-WebRequest (or related aliases like iwr/irm) together with explicit HTTP upload methods of POST or PUT. Attackers commonly use this pattern to exfiltrate or move data by sending it to external endpoints over HTTP using the script’s built-in web request capabilities. It relies on Windows PowerShell script block text telemetry to match the presence of the cmdlet and the specified -Method values.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1020/T1020.md
  - https://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
  - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-7.4
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_script_with_upload_capabilities.yml
author: frack113, Huntrule Team
date: 2022-01-07
modified: 2025-07-18
tags:
  - attack.exfiltration
  - attack.t1020
logsource:
  product: windows
  category: ps_script
  definition: bade5735-5ab0-4aa7-a642-a11be0e40872
detection:
  selection_cmdlet:
    ScriptBlockText|contains:
      - Invoke-RestMethod
      - Invoke-WebRequest
      - "irm "
      - "iwr "
  selection_flag:
    ScriptBlockText|contains:
      - -Method "POST"
      - -Method "PUT"
      - -Method POST
      - -Method PUT
      - -Method 'POST'
      - -Method 'PUT'
  condition: all of selection_*
falsepositives:
  - Unknown
level: low
license: DRL-1.1
related:
  - id: d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
    type: derived

What it detects

This rule flags PowerShell script blocks that include Invoke-WebRequest (or related aliases like iwr/irm) together with explicit HTTP upload methods of POST or PUT. Attackers commonly use this pattern to exfiltrate or move data by sending it to external endpoints over HTTP using the script’s built-in web request capabilities. It relies on Windows PowerShell script block text telemetry to match the presence of the cmdlet and the specified -Method values.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.