Malicious Nishang PowerShell Commandlets
Description
Detects Commandlet names and arguments from the Nishang exploitation framework
Query · sigma
selection: ScriptBlockText|contains: - Add-ConstrainedDelegationBackdoor - Copy-VSS - Create-MultipleSessions - DataToEncode - DNS_TXT_Pwnage - Do-Exfiltration-Dns - Download_Execute - Download-Execute-PS - DownloadAndExtractFromRemoteRegistry - DumpCerts - DumpCreds - DumpHashes - Enable-DuplicateToken - Enable-Duplication - Execute-Command-MSSQL - Execute-DNSTXT-Code - Execute-OnTime - ExetoText - exfill - ExfilOption - FakeDC - FireBuster - FireListener - 'Get-Information ' - Get-PassHints - Get-Web-Credentials - Get-WebCredentials - Get-WLAN-Keys - HTTP-Backdoor - Invoke-AmsiBypass - Invoke-BruteForce - Invoke-CredentialsPhish - Invoke-Decode - Invoke-Encode - Invoke-Interceptor - Invoke-JSRatRegsvr - Invoke-JSRatRundll - Invoke-MimikatzWDigestDowngrade - Invoke-NetworkRelay - Invoke-PowerShellIcmp - Invoke-PowerShellUdp - Invoke-Prasadhak - Invoke-PSGcat - Invoke-PsGcatAgent - Invoke-SessionGopher - Invoke-SSIDExfil - LoggedKeys - Nishang - NotAllNameSpaces - Out-CHM - OUT-DNSTXT - Out-HTA - Out-RundllCommand - Out-SCF - Out-SCT - Out-Shortcut - Out-WebQuery - Out-Word - Parse_Keys - Password-List - Powerpreter - Remove-Persistence - Remove-PoshRat - Remove-Update - Run-EXEonRemote - Set-DCShadowPermissions - Set-RemotePSRemoting - Set-RemoteWMI - Shellcode32 - Shellcode64 - StringtoBase64 - TexttoExe condition: selection
Known false positives
- Unknown