UC-L3-020
Encoded PowerShell Command
Windows Security / Sysmon Event ID 1
Use case development / Detect Malware Infections / Detect Malware Execution
sigma
Detection rule
title: Encoded PowerShell Command Execution
status: experimental
description: Detects execution of encoded PowerShell commands
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- '-enc'
- '-EncodedCommand'
- '-e '
condition: selection
falsepositives:
- Legitimate encoded scripts
level: high
tags:
- attack.execution
- attack.t1059.001Test cases
- Execute base64 encoded PowerShell
False positive guidance
Whitelist known legitimate automation scripts.