diff --git a/rules/windows/sysmon/sysmon_powershell_suspicious_parameter_combo.yml b/rules/windows/sysmon/sysmon_powershell_suspicious_parameter_combo.yml new file mode 100644 index 000000000..c9466ed7b --- /dev/null +++ b/rules/windows/sysmon/sysmon_powershell_suspicious_parameter_combo.yml @@ -0,0 +1,18 @@ +title: Suspicious PowerShell Parameter Combination +status: experimental +description: Detects suspicious PowerShell invocation command parameters +author: Florian Roth +logsource: + product: sysmon +detection: + keywords: + - 'powershell' + - ' -nop ' + - ' -w hidden ' + - ' -exec bypass ' + - ' -enc ' + condition: all of keywords +falsepositives: + - Penetration tests + - Very special / sneaky PowerShell scripts +level: high