Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools

Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-02
Updated
2026-07-30

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the command line contains the names of PowerShell commandlets associated with common offensive PowerShell tooling. Attackers rely on these modules to perform credential access, discovery, persistence, exfiltration, and privilege escalation using PowerShell-based execution. The detection relies on process_creation telemetry that includes the full process command line text.

Reporting behind it

Related detections9 linkedT1069.002 — drag to rearrange
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Windows file creation for SharpHound/BloodHound collection output filenames
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows Process Creation: Execution of Net.exe or Net1.exe
Suspicious Group Discovery - Command (via process_creation)
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Pivot detection · T1069.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.