title: Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell id: 1b9dc62e-6e9e-42a3-8990-94d7a10007f7 status: test description: Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block \u2014 references: - https://github.com/danielbohannon/Invoke-Obfuscation/blob/f20e7f843edd0a3a7716736e9eddfa423395dd26/Out-ObfuscatedStringCommand.ps1#L873-L888 author: 'Daniel Bohannon (@Mandiant/@FireEye), oscd.community' date: 2019-11-08 modified: 2022-12-31 tags: - attack.stealth - attack.t1027 - attack.execution - attack.t1059.001 logsource: product: windows category: ps_script definition: 'Requirements: Script Block Logging must be enabled' detection: selection_iex: - ScriptBlockText|re: '\$PSHome\[\s*\d{1,3}\s*\]\s*\+\s*\$PSHome\[' - ScriptBlockText|re: '\$ShellId\[\s*\d{1,3}\s*\]\s*\+\s*\$ShellId\[' - ScriptBlockText|re: '\$env:Public\[\s*\d{1,3}\s*\]\s*\+\s*\$env:Public\[' - ScriptBlockText|re: '\$env:ComSpec\[(\s*\d{1,3}\s*,){2}' - ScriptBlockText|re: '\*mdr\*\W\s*\)\.Name' - ScriptBlockText|re: '\$VerbosePreference\.ToString\(' condition: selection_iex falsepositives: - Unknown level: high