Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
- Product
- windows
- Service
- security
- Author
- Timur Zinniatullin, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-10-13
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows Security event ID 4697 where the recorded ServiceFileName contains patterns indicative of obfuscated PowerShell execution using VAR++ LAUNCHER techniques. Attackers may use this obfuscation to hinder detection and analysis while launching PowerShell payloads. The detection relies on Security audit telemetry that logs event 4697 along with the ServiceFileName string content for matching substrings.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
id: b180f0c5-7296-4075-af53-ef34895c4e76
related:
- id: 14bcba49-a428-42d9-b943-e2ce0f0f7ae6
type: derived
- id: 4c54ba8f-73d2-4d40-8890-d9cf1dca3d30
type: derived
status: test
description: This rule flags Windows Security event ID 4697 where the recorded ServiceFileName contains patterns indicative of obfuscated PowerShell execution using VAR++ LAUNCHER techniques. Attackers may use this obfuscation to hinder detection and analysis while launching PowerShell payloads. The detection relies on Security audit telemetry that logs event 4697 along with the ServiceFileName string content for matching substrings.
references:
- https://github.com/SigmaHQ/sigma/issues/1009
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_invoke_obfuscation_via_var_services_security.yml
author: Timur Zinniatullin, oscd.community, Huntrule Team
date: 2020-10-13
modified: 2022-11-29
tags:
- attack.stealth
- attack.t1027
- attack.execution
- attack.t1059.001
logsource:
product: windows
service: security
definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
selection:
EventID: 4697
ServiceFileName|contains|all:
- "&&set"
- cmd
- /c
- -f
ServiceFileName|contains:
- "{0}"
- "{1}"
- "{2}"
- "{3}"
- "{4}"
- "{5}"
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1