Elastic low deprecated kql
Deprecated - Potential PowerShell Obfuscated Script
Identifies scripts that contain patterns and known methods that obfuscate PowerShell code. Attackers can use obfuscation techniques to bypass PowerShell security protections such as Antimalware Scan Interface (AMSI).
Detection Logic
event.category:process and host.os.type:windows and
powershell.file.script_block_text : (
"[string]::join" or
"-Join" or
"[convert]::toint16" or
"[char][int]$_" or
("ConvertTo-SecureString" and "PtrToStringAuto") or
"-BXor" or
("replace" and "char") or
"[array]::reverse" or
"-replace"
) and
powershell.file.script_block_text : (
("$pSHoMe[" and "+$pSHoMe[") or
("$ShellId[" and "+$ShellId[") or
("$env:ComSpec[4" and "25]-Join") or
(("Set-Variable" or "SV" or "Set-Item") and "OFS") or
("*MDR*" and "Name[3,11,2]") or
("$VerbosePreference" and "[1,3]+'X'-Join''") or
("rahc" or "ekovin" or "gnirts" or "ecnereferpesobrev" or "ecalper" or "cepsmoc" or "dillehs") or
("System.Management.Automation.$([cHAr]" or "System.$([cHAr]" or ")+[cHAR]([byte]")
) and
not powershell.file.script_block_text : (
("Copyright (c) 2018 Ansible Project" or "Export-ModuleMember -Function Add-CSharpType") and
("[Object]$AnsibleModule" or "$AnsibleModule.Tmpdir")
) Field Validations
Loading…
Comments (0)
Loading comments...