Non Interactive PowerShell Process Spawned
Description
Detects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.
Query · sigma
selection: - Image|endswith: - \powershell.exe - \pwsh.exe - OriginalFileName: - PowerShell.EXE - pwsh.dll filter_main_generic: ParentImage|endswith: - :\Windows\explorer.exe - :\Windows\System32\CompatTelRunner.exe - :\Windows\SysWOW64\explorer.exe filter_main_windows_update: ParentImage: :\$WINDOWS.~BT\Sources\SetupHost.exe filter_optional_vscode: ParentImage|endswith: \AppData\Local\Programs\Microsoft VS Code\Code.exe ParentCommandLine|contains: ' --ms-enable-electron-run-as-node ' filter_optional_terminal: ParentImage|contains: :\Program Files\WindowsApps\Microsoft.WindowsTerminal_ ParentImage|endswith: \WindowsTerminal.exe filter_optional_defender: ParentImage|endswith: :\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exe condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Likely. Many admin scripts and tools leverage PowerShell in their BAT or VB scripts which may trigger this rule often. It is best to add additional filters or use this to hunt for anomalies