BIOC
Low
✕
Collecting audio via PowerShell command
An attacker may collect audio from the microphone using PowerShell.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Collection
- Status:
- Enabled
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Audio Capture (T1123)
Indicator:
Process action type = execution AND target process cmd = *Get-DefaultAudioDevice* , *Get-AudioDeviceList* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDeviceVolume* , *Get-DefaultAudioDeviceVolume* , *Set-DefaultAudioDeviceMute* , *Write-DefaultAudioDeviceValue* AND target process name = powershell.exe
Preventable: yes