Skip to content
Threat Feed
medium advisory

Detection of Malicious PowerShell Command-Line Patterns

This detection analytic identifies suspicious PowerShell activity by monitoring command-line strings for patterns associated with known offensive security toolkits used for credential theft, lateral movement, and persistence.

This detection analytic targets the execution of offensive security toolkits commonly used by adversaries to facilitate post-exploitation activities such as credential theft, lateral movement, and persistence. By analyzing process execution telemetry (including Event ID 4688 or Sysmon Event ID 1) mapped to the Endpoint data model, the detection flags PowerShell command-line arguments that match known malicious patterns. This approach is instrumental for identifying unauthorized access and privilege escalation attempts. The analytic supports organizations in identifying activities related to well-known offensive frameworks, including PowerSploit, PowerShell Empire, and PowerSharpPack, by leveraging lookups of known malicious string indicators within command execution logs.

Attack Chain

  1. An adversary gains initial access to a target Windows endpoint.
  2. The adversary executes a PowerShell command directly via command-line or via a wrapper process.
  3. The PowerShell process logs the full command-line string through security logging mechanisms.
  4. Security telemetry (Sysmon or Windows Security Events) captures the process creation event.
  5. The detection engine ingests process telemetry and maps it to the Endpoint data model.
  6. The system performs a lookup against a curated list of known offensive PowerShell strings.
  7. If a match is identified, a security alert is generated for analyst investigation into potential lateral movement or credential theft.

Impact

Successful exploitation of these techniques allows adversaries to execute arbitrary code, steal sensitive credentials, move laterally within the network, and establish long-term persistence on compromised endpoints. If left undetected, this can lead to full system compromise and exfiltration of sensitive organizational data.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Deploy the analytic search to your SIEM to monitor for known malicious PowerShell strings.
  • Ensure Windows Event Log (4688) or Sysmon (Event ID 1) telemetry is enabled and correctly mapped to the CIM Endpoint data model.
  • Ingest full command-line executions to allow for accurate string matching against known offensive toolkits.
  • Review the findings generated by the analytic to investigate potential unauthorized activity on endpoints.

Immediate actions

Implement PowerShell command-line logging and ingest into the Endpoint data model.

Detection Engineering 72h

Threat Hunt

Search for PowerShell processes with high-entropy or encoded command strings.

T1059.001 medium medium confidence hunt now

Data: Process command line

Detection coverage 1

Detect Malicious PowerShell Command Strings

medium

Detects known malicious command-line strings associated with offensive PowerShell toolkits.

sigma tactics: execution techniques: T1059.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →