title: Suspicious PowerShell Invocations - Generic - PowerShell Module id: bbb80e91-5746-4fbe-8898-122e2cafdbf4 related: - id: 3d304fda-78aa-43ed-975c-d740798a49c1 type: derived - id: ed965133-513f-41d9-a441-e38076a0798f type: similar status: test description: Detects suspicious PowerShell invocation command parameters references: - Internal Research author: Florian Roth (Nextron Systems) date: 2017-03-12 modified: 2023-01-03 tags: - attack.execution - attack.t1059.001 logsource: product: windows category: ps_module definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b detection: selection_encoded: ContextInfo|contains: - ' -enc ' - ' -EncodedCommand ' - ' -ec ' selection_hidden: ContextInfo|contains: - ' -w hidden ' - ' -window hidden ' - ' -windowstyle hidden ' - ' -w 1 ' selection_noninteractive: ContextInfo|contains: - ' -noni ' - ' -noninteractive ' condition: all of selection* falsepositives: - Very special / sneaky PowerShell scripts level: high