Detection of Offensive PowerShell Toolkit Execution
This detection monitors PowerShell Script Block Logging (EventCode 4104) to identify patterns indicative of credential theft, lateral movement, and persistence used by offensive toolkits.
Security operations teams can identify the use of offensive PowerShell toolkits by leveraging EventCode 4104 (Script Block Logging). This logging mechanism captures the full content of executed PowerShell blocks, which is essential for visibility into encoded or obfuscated commands that would otherwise be obscured in standard process creation logs. By monitoring for specific strings associated with well-known frameworks like PowerSploit, Empire, and PowerSharpPack, defenders can detect activities related to credential theft, persistence, and lateral movement. This detection strategy is a fundamental requirement for environments where PowerShell is a primary vector for post-exploitation activities and provides the granular telemetry necessary to identify unauthorized access attempts before significant impact occurs.
Impact
Successful exploitation using these offensive toolkits enables attackers to perform post-exploitation activities such as credential dumping from memory, lateral movement across the network using stolen tokens, and the establishment of persistence via registry or scheduled task modifications. Failure to detect these activities at the execution stage significantly increases the risk of data exfiltration and complete system compromise within the Windows environment.
Recommendation
Deploy the provided Sigma rule and ensure PowerShell operational logging is enabled. Prioritize the ingestion of EventCode 4104 logs into the SIEM and tune the detection based on legitimate administrative scripting behavior within the environment.
Immediate actions
Enable PowerShell Script Block Logging (EventCode 4104) across all endpoints via Group Policy
Threat Hunt
Search for high-entropy PowerShell command lines or blocks containing common framework function names
Data: EventCode 4104 log data
Mitigations
Implement Constrained Language Mode (CLM) for standard users to limit the effectiveness of offensive PowerShell toolkits
T1059.001
Detection coverage 1
Detect Known Malicious PowerShell Script Blocks
mediumDetects execution of PowerShell commands containing known malicious strings associated with offensive toolkits via EventCode 4104
Detection queries are available on the platform. Get full rules →