Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block

Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-23
Updated
2026-07-31

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule flags PowerShell script blocks that use .NET SslStream client-side authentication with explicit remote certificate validation callbacks. Attackers can use these APIs to establish encrypted channels for command and control while handling certificates in code. The detection relies on PowerShell Script Block Logging and matches specific .NET method and callback strings within the logged script content.

Related detections5 linkedT1573 — drag to rearrange
Malicious OysterLoader C2 Beacon Using WordPressAgent User Agent
Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Microsoft Cloud App Security: Alerts for Successful Activity from Infrequent Countries
Microsoft Cloud App Security: Activity from Microsoft Threat Intelligence Risky IPs
M365 Threat Management: Activity from Anonymous Proxy IP Addresses
Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Pivot detection · T1573 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.