title: Suspicious PowerShell Invocations - Generic id: ed965133-513f-41d9-a441-e38076a0798f related: - id: 3d304fda-78aa-43ed-975c-d740798a49c1 type: derived - id: bbb80e91-5746-4fbe-8898-122e2cafdbf4 type: similar status: test description: Detects suspicious PowerShell invocation command parameters references: - Internal Research author: Florian Roth (Nextron Systems) date: 2017-03-12 modified: 2023-01-03 tags: - attack.execution - attack.t1059.001 logsource: product: windows category: ps_script definition: 'Requirements: Script Block Logging must be enabled' detection: selection_encoded: ScriptBlockText|contains: - ' -enc ' - ' -EncodedCommand ' - ' -ec ' selection_hidden: ScriptBlockText|contains: - ' -w hidden ' - ' -window hidden ' - ' -windowstyle hidden ' - ' -w 1 ' selection_noninteractive: ScriptBlockText|contains: - ' -noni ' - ' -noninteractive ' condition: all of selection* falsepositives: - Very special / sneaky PowerShell scripts level: high