Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies PowerShell downloading files from external sources, a common malware delivery technique. Covers Invoke-WebRequest, Invoke-RestMethod and Start-BitsTransfer, the curl and wget aliases, and .NET classes System.Net.WebClient and HttpClient.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | c7b320fb-ac67-45b0-92c4-b0f1e10b4e46 |
| Tactics | CommandAndControl, Execution |
| Techniques | T1059.001, T1105 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
CommandLine has_any "Invoke-WebRequest"NewProcessName has_any "powershell.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊