Windows PowerShell ScriptBlock keyword match for WinPwn tool usage

Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_script
Author
Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
Published
2023-12-04
Updated
2026-07-31

What it detects

This rule identifies PowerShell ScriptBlock text containing specific strings associated with the WinPwn tool, including references to WinPwn.exe, WinPwn.ps1, and related identifiers. Such scripted tool execution and recon/exploitation behavior is high risk because it can indicate credential access, discovery, or privilege escalation attempts in Windows environments. It relies on PowerShell Script Block Logging telemetry, matching on ScriptBlockText content within executed script blocks.

Related detections9 linkedT1555.003 — drag to rearrange
Windows process command line matches WinPwn tool execution keywords
Suspicious RegAsm MSBuild or AutoIt Accessing Browser Credential Stores
Suspicious Offensive Recon and Credential Tools Execution (via process_creation)
Windows: Detect winPEAS privilege escalation reconnaissance execution
Suspicious ALPHA SPIDER Veeam Backup Credential Extraction (via process_creation)
Malicious FodHelper UAC Bypass via ms-settings Shell Command Hijack (via registry_set)
Suspicious Clipboard Data Access via Get-Clipboard (BeaverTail OtterCookie)
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious System Profiler Hardware Enumeration (via process_creation)
Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Pivot detection · T1555.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.