Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX

Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-11-09
Updated
2026-07-31

What it detects

This rule flags Windows process creation events whose command line contains a PowerShell hidden, no-profile execution pattern that runs IEX with a WebClient downloadstring to retrieve remote content. Such behavior is commonly used by attackers to stage payloads like Cobalt Strike without writing a dropper to disk. It relies on process creation telemetry with command-line visibility to match the specific execution string.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.