PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
PowerShell scripts referencing Invoke-WebRequest with -Method POST/PUT indicate potential data upload behavior.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-01-07
- Updated
- 2026-07-31
ATT&CK techniques
ExfiltrationRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows PowerShell script content that invokes Invoke-WebRequest (or common aliases) and specifies HTTP upload semantics via POST or PUT. Attackers use these methods to send data to external endpoints, making the behavior a useful indicator of potential exfiltration or staging. It relies on ScriptBlockText telemetry capturing both the cmdlet usage and the HTTP -Method argument values.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1020/T1020.md
- w3.orghttps://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
- learn.microsoft.comhttps://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-7.4
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_script_with_upload_capabilities.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
id: cab463e3-49b0-4fe2-aa8d-606e2b4e8559
status: test
description: This rule flags Windows PowerShell script content that invokes Invoke-WebRequest (or common aliases) and specifies HTTP upload semantics via POST or PUT. Attackers use these methods to send data to external endpoints, making the behavior a useful indicator of potential exfiltration or staging. It relies on ScriptBlockText telemetry capturing both the cmdlet usage and the HTTP -Method argument values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1020/T1020.md
- https://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-7.4
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_script_with_upload_capabilities.yml
author: frack113, Huntrule Team
date: 2022-01-07
modified: 2025-07-18
tags:
- attack.exfiltration
- attack.t1020
logsource:
product: windows
category: ps_script
definition: bade5735-5ab0-4aa7-a642-a11be0e40872
detection:
selection_cmdlet:
ScriptBlockText|contains:
- Invoke-RestMethod
- Invoke-WebRequest
- "irm "
- "iwr "
selection_flag:
ScriptBlockText|contains:
- -Method "POST"
- -Method "PUT"
- -Method POST
- -Method PUT
- -Method 'POST'
- -Method 'PUT'
condition: all of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1
related:
- id: d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
type: derived