Files
splunk-security_content/docs/_stories/malicious_powershell.md
T
2021-09-20 20:45:22 -04:00

5.0 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Malicious PowerShell 2017-08-23 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Description

Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent.

  • ID: 2c8ff66e-0b57-42af-8ad7-912438a403fc
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2017-08-23
  • Author: David Dorsey, Splunk

Detection profiles

Name Technique Type
Any Powershell DownloadFile None TTP
Any Powershell DownloadString None TTP
Credential Extraction indicative of use of DSInternals credential conversion modules None TTP
Credential Extraction indicative of use of DSInternals modules None TTP
Credential Extraction indicative of use of PowerSploit modules None TTP
Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals None TTP
Detect Empire with PowerShell Script Block Logging None TTP
Detect Mimikatz With PowerShell Script Block Logging None TTP
Illegal Access To User Content via PowerSploit modules None TTP
Illegal Privilege Elevation and Persistence via PowerSploit modules None TTP
Illegal Service and Process Control via PowerSploit modules None TTP
Malicious PowerShell Process - Connect To Internet With Hidden Window None TTP
Malicious PowerShell Process - Encoded Command None Hunting
Malicious PowerShell Process With Obfuscation Techniques None TTP
PowerShell 4104 Hunting None Hunting
PowerShell Domain Enumeration None TTP
PowerShell Loading DotNET into Memory via System Reflection Assembly None TTP
Powershell Creating Thread Mutex None TTP
Powershell Enable SMB1Protocol Feature None TTP
Powershell Execute COM Object None TTP
Powershell Fileless Process Injection via GetProcAddress None TTP
Powershell Fileless Script Contains Base64 Encoded Content None TTP
Powershell Processing Stream Of Data None TTP
Powershell Using memory As Backing Store None TTP
Recon AVProduct Through Pwh or WMI None TTP
Recon Using WMI Class None TTP
Set Default PowerShell Execution Policy To Unrestricted or Bypass None TTP
Unloading AMSI via Reflection None TTP
WMI Recon Running Process Or Services None TTP

Reference

source | version: 5