BIOC Low

Collecting audio via PowerShell command

An attacker may collect audio from the microphone using PowerShell.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Collection
Status:
Enabled
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Audio Capture (T1123)
Indicator:

Process action type = execution AND target process cmd = *Get-DefaultAudioDevice* , *Get-AudioDeviceList* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDeviceVolume* , *Get-DefaultAudioDeviceVolume* , *Set-DefaultAudioDeviceMute* , *Write-DefaultAudioDeviceValue* AND target process name = powershell.exe

Preventable: yes