Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)

Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-03-08
Updated
2026-07-31

What it detects

This rule identifies Windows process creation where the command line contains a specific PowerShell flag sequence associated with the Wmiexec script behavior. Attackers may use these flags to run PowerShell non-interactively and hidden, while enabling execution bypass and using encoded payload delivery. Telemetry relies on process creation events with access to the full command line for matching the exact flag substring.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.