BIOC Medium

PowerShell reverse shell

This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell.

Module:
Platform Analytics
Agent event type:
Network
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Indicator:

Network action type = outgoing , failed AND remote port = 4444 Process initiator cmd = *web*downloadstring*.ps1* , *web*downloadstring*.exe* AND initiated by = powershell.exe

Preventable: yes