Network Connection Initiated By PowerShell Process
Description
Detects a network connection that was initiated from a PowerShell process. Often times malicious powershell scripts download additional payloads or communicate back to command and control channels via uncommon ports or IPs. Use this rule as a basis for hunting for anomalies.
Query · sigma
selection: Image|endswith: - \powershell.exe - \pwsh.exe Initiated: 'true' filter_main_local_ip: DestinationIp|cidr: - 127.0.0.0/8 - 10.0.0.0/8 - 169.254.0.0/16 - 172.16.0.0/12 - 192.168.0.0/16 - ::1/128 - fe80::/10 - fc00::/7 User|contains: - AUTHORI - AUTORI filter_main_msrange: DestinationIp|cidr: - 20.184.0.0/13 - 51.103.210.0/23 condition: selection and not 1 of filter_main_*
Known false positives
- Administrative scripts
- Microsoft IP range
- Additional filters are required. Adjust to your environment (e.g. extend filters with company's ip range')