Skip to content
Threat Feed
high advisory

PowerShell Dynamic Module Invocation via ExportedCommands Array Indexing

Attackers are leveraging obfuscated PowerShell command lines to dynamically invoke cmdlets via array index values of exported module commands, effectively bypassing signature-based detection for sensitive function names.

This technique involves a stealthy method of PowerShell command execution where attackers avoid invoking sensitive cmdlets, such as 'Invoke-Expression' or 'Invoke-RestMethod', directly by name. Instead, the actor enumerates the 'ExportedCommands' property of the 'Microsoft.PowerShell.Utility' module, converts these commands into an indexed array, and invokes the desired functionality using the integer index of the command.

By utilizing index-based access, the malicious payload is obfuscated within the command line, rendering string-based detection rules ineffective. This method is particularly dangerous for defenders who rely heavily on monitoring for specific command-line keywords to identify suspicious script execution. This technique has been observed as a means to achieve code execution while evading standard monitoring controls.

Attack Chain

  1. Attacker prepares a PowerShell script containing the obfuscated index-based invocation logic.
  2. The PowerShell engine (powershell.exe or pwsh.exe) is executed on the target endpoint.
  3. The script executes 'Get-Module -ListAvailable Microsoft.PowerShell.Utility' to retrieve available cmdlets.
  4. The script accesses the 'ExportedCommands.Values' collection to enumerate available functions.
  5. The attacker identifies the index corresponding to the target command (e.g., Invoke-WebRequest).
  6. The target command is invoked indirectly using the array syntax, such as '& $commandArray[$index]'.
  7. The script downloads or executes the final malicious payload, such as a secondary stager or script file.

Impact

Successful execution allows attackers to execute arbitrary code with the privileges of the PowerShell process, enabling stealthy downloading of malware, secondary stager deployment, or system reconnaissance while bypassing perimeter and endpoint security monitoring.

Recommendation

Deploy the provided Sigma rule to detect the specific combination of module enumeration and array-indexed command invocation. Enable command-line logging via Sysmon (Event ID 1) or PowerShell Script Block Logging (Event ID 4104) to capture the full, de-obfuscated script content for investigation.


Immediate actions

Deploy Sigma detection rule to SIEM

Detection Engineering 48h

Threat Hunt

Search command-line logs for 'ExportedCommands.Values' patterns

T1027.010 high high confidence hunt now

Data: Process creation (CommandLine)

Detection coverage 1

Detect PowerShell Dynamic Module Invocation via Array Indexing

high

Detects PowerShell processes invoking cmdlets indirectly by array index after enumerating module exports, used to evade string-based detection.

sigma tactics: execution techniques: T1027.010, T1059.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →