Potential PowerShell Obfuscation Via Reversed Commands
Description
Detects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
Query · sigma
selection_img: - Image|endswith: - \powershell.exe - \pwsh.exe - OriginalFileName: - PowerShell.EXE - pwsh.dll selection_cli: CommandLine|contains: - hctac - kaerb - dnammoc - ekovn - eliFd - rahc - etirw - golon - tninon - eddih - tpircS - ssecorp - llehsrewop - esnopser - daolnwod - tneilCbeW - tneilc - ptth - elifotevas - 46esab - htaPpmeTteG - tcejbO - maerts - hcaerof - retupmoc filter_main_encoded_keyword: CommandLine|contains: - ' -EncodedCommand ' - ' -enc ' condition: all of selection_* and not 1 of filter_main_*
Known false positives
- Unlikely