Windows WinAPI Function Calls From PowerShell Script Blocks

Find PowerShell script blocks that reference WinAPI/native-call function names tied to process, memory, token, or thread operations.

FreeUnreviewedSigmamediumv1
title: Windows WinAPI Function Calls From PowerShell Script Blocks
id: d411102a-ef98-498c-b38c-77e8226e35b5
related:
  - id: ba3f5c1b-6272-4119-9dbd-0bc8d21c2702
    type: similar
  - id: 03d83090-8cba-44a0-b02f-0b756a050306
    type: similar
  - id: 19d65a1c-8540-4140-8062-8eb00db0bba5
    type: similar
  - id: 9f22ccd5-a435-453b-af96-bf99cbb594d4
    type: derived
status: test
description: This rule flags PowerShell script block text that contains specific WinAPI and related native-call tokens, indicating attempts to invoke low-level Windows functionality from PowerShell. Such activity can help attackers perform process, memory, token, and thread operations while bypassing expectations around typical PowerShell command usage. Detection relies on Script Block Logging telemetry containing the script text patterns.
references:
  - https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/powershell/powershell_script/posh_ps_win_api_library_access.yml
author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-07-21
tags:
  - attack.execution
  - attack.t1059.001
  - attack.t1106
  - detection.threat-hunting
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains:
      - AddSecurityPackage
      - AdjustTokenPrivileges
      - CloseHandle
      - CreateProcessWithToken
      - CreateRemoteThread
      - CreateThread
      - CreateUserThread
      - DangerousGetHandle
      - DuplicateTokenEx
      - EnumerateSecurityPackages
      - FreeLibrary
      - GetDelegateForFunctionPointer
      - GetLogonSessionData
      - GetModuleHandle
      - GetProcAddress
      - GetProcessHandle
      - GetTokenInformation
      - ImpersonateLoggedOnUser
      - LoadLibrary
      - memcpy
      - MiniDumpWriteDump
      - OpenDesktop
      - OpenProcess
      - OpenProcessToken
      - OpenThreadToken
      - OpenWindowStation
      - QueueUserApc
      - ReadProcessMemory
      - RevertToSelf
      - RtlCreateUserThread
      - SetThreadToken
      - VirtualAlloc
      - VirtualFree
      - VirtualProtect
      - WaitForSingleObject
      - WriteInt32
      - WriteProcessMemory
      - ZeroFreeGlobalAllocUnicode
  condition: selection
falsepositives:
  - This rule is mainly used for hunting and will generate quite a lot of false positives when applied in production. It's best combined with other fields such as the path of execution, the parent process, etc.
level: medium
license: DRL-1.1

What it detects

This rule flags PowerShell script block text that contains specific WinAPI and related native-call tokens, indicating attempts to invoke low-level Windows functionality from PowerShell. Such activity can help attackers perform process, memory, token, and thread operations while bypassing expectations around typical PowerShell command usage. Detection relies on Script Block Logging telemetry containing the script text patterns.

Known false positives

  • This rule is mainly used for hunting and will generate quite a lot of false positives when applied in production. It's best combined with other fields such as the path of execution, the parent process, etc.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.