PowerShell Token Obfuscation (#3825)
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
title: Powershell Token Obfuscation - Powershell
|
||||
id: f3a98ce4-6164-4dd4-867c-4d83de7eca51
|
||||
related:
|
||||
- id: deb9b646-a508-44ee-b7c9-d8965921c6b6
|
||||
type: similar
|
||||
status: experimental
|
||||
description: Detects TOKEN OBFUSCATION technique from Invoke-Obfuscation
|
||||
references:
|
||||
- https://github.com/danielbohannon/Invoke-Obfuscation
|
||||
author: frack113
|
||||
date: 2022/12/27
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1027.009
|
||||
logsource:
|
||||
product: windows
|
||||
category: ps_script
|
||||
definition: Script block logging must be enabled
|
||||
detection:
|
||||
selection:
|
||||
# Examples:
|
||||
# IN`V`o`Ke-eXp`ResSIOn (Ne`W-ob`ject Net.WebClient).DownloadString
|
||||
# &('In'+'voke-Expressi'+'o'+'n') (.('New-Ob'+'jec'+'t') Net.WebClient).DownloadString
|
||||
# &("{2}{3}{0}{4}{1}"-f 'e','Expression','I','nvok','-') (&("{0}{1}{2}"-f'N','ew-O','bject') Net.WebClient).DownloadString
|
||||
# ${e`Nv:pATh}
|
||||
- ScriptBlockText|re: '\w+\`(\w+|-|.)\`[\w+|\s]'
|
||||
#- ScriptBlockText|re: '\((\'(\w|-|\.)+\'\+)+\'(\w|-|\.)+\'\)' TODO: fixme
|
||||
- ScriptBlockText|re: '"({\d})+"\s*-f'
|
||||
- ScriptBlockText|re: '\${((e|n|v)*`(e|n|v)*)+:path}|\${((e|n|v)*`(e|n|v)*)+:((p|a|t|h)*`(p|a|t|h)*)+}|\${env:((p|a|t|h)*`(p|a|t|h)*)+}'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: high
|
||||
Reference in New Issue
Block a user