PowerShell Dynamic Module Invocation Via ExportedCommands Array Index - PS Script


Description

Detects obfuscated PowerShell scripts that enumerate Microsoft.PowerShell.Utility exported commands and invoke cmdlets indirectly by array index. This can be used to evade detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.

Query · sigma

selection_module_export_enum:
  ScriptBlockText|contains:
  - 'Get-Module '
  - 'gmo '
  ScriptBlockText|contains|all:
  - ListAvailable
  - Microsoft.PowerShell.Utility
  - ExportedCommands
  - Values
selection_index_used:
  ScriptBlockText|contains: '[*]'
condition: all of selection_*

Known false positives

  • Legitimate use of exported commands array indexing in PowerShell scripts (should be rare)
Raw source PowerShell Dynamic Module Invocation Via ExportedCommands Array Index - PS Script · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: PowerShell Dynamic Module Invocation Via ExportedCommands Array Index - PS Script
id: 4ff4ad3e-9fb5-4a70-9962-d6ea58090318
related:
    - id: 0c3ebe9f-df09-4e00-be0f-73d4ca8d62f6
      type: similar
status: experimental
description: |
    Detects obfuscated PowerShell scripts that enumerate Microsoft.PowerShell.Utility exported commands
    and invoke cmdlets indirectly by array index. This can be used to evade detections
    that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
references:
    - https://www.linkedin.com/posts/mark-o-halloran1_clickfix-defense-evasion-tactic-today-i-ugcPost-7453463467736408064-snrp/
author: Norbert Jaśniewicz (AlphaSOC)
date: 2026-10-06
tags:
    - attack.execution
    - attack.stealth
    - attack.t1027
    - attack.t1059.001
logsource:
    product: windows
    category: ps_script
    definition: 'Requirements: Script Block Logging must be enabled'
detection:
    selection_module_export_enum:
        ScriptBlockText|contains:
            - 'Get-Module '
            - 'gmo '
        ScriptBlockText|contains|all:
            - 'ListAvailable'
            - 'Microsoft.PowerShell.Utility'
            - 'ExportedCommands'
            - 'Values'
    selection_index_used:
        ScriptBlockText|contains: '[*]'
    condition: all of selection_*
falsepositives:
    - Legitimate use of exported commands array indexing in PowerShell scripts (should be rare)
level: medium
regression_tests_path: regression_data/rules/windows/powershell/powershell_script/posh_ps_cmdlet_invocation_via_exported_commands_array_index/info.yml

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.