Potential Obfuscated PowerShell Script
Description
Identifies the execution of PowerShell with potentially obfuscated content. This behavior is often observed during malware installation leveraging PowerShell.
Query · eql
api where process.Ext.api.name == "AmsiScanBuffer" and
process.Ext.api.parameters.app_name == "PowerShell" and
(
process.Ext.api.parameters.buffer regex """.*(\"\{[0-9]{1,2}\}\{[0-9]{1,2}\}\{[0-9]{1,2}\}|['\"] {0,2}\+ {0,2}['\"][^$]{1,25}['\"]{0,2}\+ {0,2}['\"][^$]{1,25}['\"]\+['\"][^$]{1,25}['\"]\+['\"]).*""" or
process.Ext.api.parameters.buffer regex~ """.*\.\"s(`+e`*t`*v`*a`*l`*u`*e)|(`*e`+t`*v`*a`*l`*u`*e)|(`*e`*t`+v`*a`*l`*u`*e)|(`*e`*t`*v`+a`*l`*u`*e)|(`*e`*t`*v`*a`+l`*u`*e)|(`*e`*t`*v`*a`*l`+u`*e)|(`*e`*t`*v`*a`*l`*u`+e).*"""
) and
not (user.id == "S-1-5-18" and process.Ext.api.parameters.content_name == "C:\\Install-Beats.ps1" and process.Ext.api.parameters.buffer like "*Install-Beat($ElasticAgent)*") and
not process.Ext.api.parameters.buffer :
("*:::::\\windows\\sentinel\\*", "*<#sentinelbreakpoints#>*", "*$merged_stderr*", "*$branchStatusTextSpan.Text*") and
not (user.id == "S-1-5-18" and process.Ext.api.parameters.content_name : "C:\\WINDOWS\\CCM\\*.ps1") and
not process.Ext.api.parameters.content_name : ("C:\\Program Files\\Microsoft Azure AD Connect Health Agent\\Products\\AdFederationService\\AdfsDiagnostics\\AdfsToolbox\\diagnosticsModule\\Private\\CommonHealthChecks.ps1") and
not process.parent.executable : "C:\\Program Files\\ConEmu\\ConEmu\\ConEmuC64.exe"