Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0455 — Abuse of PowerShell for Arbitrary Execution
DET0455

Abuse of PowerShell for Arbitrary Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1252 Analytic 1252
Windows

Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.

WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:PowerShell EventCode=400, 403 WinEventLog:Sysmon EventCode=7
[CommandLinePattern] Regex pattern for encoded, obfuscated, or hidden PowerShell arguments (e.g., '-enc', '-nop').
[ParentProcessName] Filter based on abnormal parents like Excel, WinWord, or mshta spawning PowerShell.
[TimeWindow] Scope detection to off-hours, lateral movement timeframes, or non-maintenance windows.
[LoadedModuleList] Tuneable to monitor rare or never-before-seen .NET assemblies tied to PowerShell abuse.
[ScriptBlockLengthThreshold] Adjustable threshold for length of script blocks logged by Event ID 4104 (useful for filtering noise).

Detected Techniques

1

Details

MITRE ID
DET0455
STIX ID
x-mitre-detection-strategy--72b209e2-8c65-4217-8532-fabd0cb54ae5
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.