PowerShell Dynamic Module Invocation via ExportedCommands Array Indexing
Attackers are leveraging obfuscated PowerShell command lines to dynamically invoke cmdlets via array index values of exported module commands, effectively bypassing signature-based detection for sensitive function names.
This technique involves a stealthy method of PowerShell command execution where attackers avoid invoking sensitive cmdlets, such as 'Invoke-Expression' or 'Invoke-RestMethod', directly by name. Instead, the actor enumerates the 'ExportedCommands' property of the 'Microsoft.PowerShell.Utility' module, converts these commands into an indexed array, and invokes the desired functionality using the integer index of the command.
By utilizing index-based access, the malicious payload is obfuscated within the command line, rendering string-based detection rules ineffective. This method is particularly dangerous for defenders who rely heavily on monitoring for specific command-line keywords to identify suspicious script execution. This technique has been observed as a means to achieve code execution while evading standard monitoring controls.
Attack Chain
- Attacker prepares a PowerShell script containing the obfuscated index-based invocation logic.
- The PowerShell engine (powershell.exe or pwsh.exe) is executed on the target endpoint.
- The script executes 'Get-Module -ListAvailable Microsoft.PowerShell.Utility' to retrieve available cmdlets.
- The script accesses the 'ExportedCommands.Values' collection to enumerate available functions.
- The attacker identifies the index corresponding to the target command (e.g., Invoke-WebRequest).
- The target command is invoked indirectly using the array syntax, such as '& $commandArray[$index]'.
- The script downloads or executes the final malicious payload, such as a secondary stager or script file.
Impact
Successful execution allows attackers to execute arbitrary code with the privileges of the PowerShell process, enabling stealthy downloading of malware, secondary stager deployment, or system reconnaissance while bypassing perimeter and endpoint security monitoring.
Recommendation
Deploy the provided Sigma rule to detect the specific combination of module enumeration and array-indexed command invocation. Enable command-line logging via Sysmon (Event ID 1) or PowerShell Script Block Logging (Event ID 4104) to capture the full, de-obfuscated script content for investigation.
Immediate actions
Deploy Sigma detection rule to SIEM
Threat Hunt
Search command-line logs for 'ExportedCommands.Values' patterns
Data: Process creation (CommandLine)
Detection coverage 1
Detect PowerShell Dynamic Module Invocation via Array Indexing
highDetects PowerShell processes invoking cmdlets indirectly by array index after enumerating module exports, used to evade string-based detection.
Detection queries are available on the platform. Get full rules →