title: Alternate PowerShell Hosts id: fe6e002f-f244-4278-9263-20e4b593827f description: Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe status: experimental date: 2019/09/12 modified: 2021/12/07 author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) tags: - attack.execution - attack.t1059.001 references: - https://threathunterplaybook.com/notebooks/windows/02_execution/WIN-190610201010.html logsource: product: windows category: image_load detection: selection: Description: 'System.Management.Automation' ImageLoaded|contains: 'System.Management.Automation' filter: - Image|endswith: - '\powershell.exe' - '\mscorsvw.exe' - Image|startswith: - 'C:\Program Files (x86)\Microsoft Visual Studio\' - 'C:\Program Files\Microsoft Visual Studio\' - 'C:\Windows\System32\' condition: selection and not filter falsepositives: - Unknown level: medium