Security Software Discovery Via Powershell Script
Description
Detects calls to "get-process" where the output is piped to a "where-object" filter to search for security solution processes. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as firewall rules and anti-virus
Query · sigma
selection_cmdlet: ScriptBlockText|contains: - get-process | \? - get-process | where - gps | \? - gps | where selection_field: ScriptBlockText|contains: - Company -like - Description -like - Name -like - Path -like - Product -like selection_keywords: ScriptBlockText|contains: - \*avira\* - \*carbonblack\* - \*cylance\* - \*defender\* - \*kaspersky\* - \*malware\* - \*sentinel\* - \*symantec\* - \*virus\* condition: all of selection_*
Known false positives
- False positives might occur due to the nature of the ScriptBlock being ingested as a big blob. Initial tuning is required.
- As the "selection_cmdlet" is common in scripts the matching engine might slow down the search. Change into regex or a more accurate string to avoid heavy resource consumption if experienced