Detection: Powershell Processing Stream Of Data

Description

The following analytic detects suspicious PowerShell script execution involving compressed stream data processing, identified via EventCode 4104. It leverages PowerShell Script Block Logging to flag scripts using IO.Compression, IO.StreamReader, or decompression methods. This activity is significant as it often indicates obfuscated PowerShell or embedded .NET/binary execution, which are common tactics for evading detection. If confirmed malicious, this behavior could allow attackers to execute hidden code, escalate privileges, or maintain persistence within the environment.

 1`powershell`
 2EventCode=4104
 3ScriptBlockText IN (
 4    "*IO.Compression.*",
 5    "*IO.StreamReader*",
 6    "*]::Decompress*"
 7)
 8
 9| fillnull
10
11| stats count min(_time) as firstTime
12              max(_time) as lastTime
13  by dest signature signature_id
14     user_id vendor_product EventID
15     Guid Opcode Name
16     Path ProcessID ScriptBlockId
17     ScriptBlockText
18  
19| `security_content_ctime(firstTime)`
20  
21| `security_content_ctime(lastTime)`
22  
23| `powershell_processing_stream_of_data_filter`

Data Source

Name Platform Sourcetype Source
Powershell Script Block Logging 4104 Windows icon Windows 'XmlWinEventLog' 'XmlWinEventLog:Microsoft-Windows-PowerShell/Operational'

Macros Used

Name Value
powershell (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational" OR source=WinEventLog:PowerShellCore/Operational OR source="XmlWinEventLog:PowerShellCore/Operational")
powershell_processing_stream_of_data_filter search *
powershell_processing_stream_of_data_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule 0 * * * *
Earliest Time -70m@m
Latest Time -10m@m
Schedule Window auto
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) Yes
Anomaly detections generate Intermediate Findings (Risk Events). They do not generate a Finding (Notable) directly.

Implementation

To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://help.splunk.com/en/security-offerings/splunk-user-behavior-analytics/get-data-in/5.4.1/add-other-data-to-splunk-uba/configure-powershell-logging-to-see-powershell-anomalies-in-splunk-uba.

Known False Positives

powershell may used this function to process compressed data.

Associated Analytic Story

Intermediate Findings

Message Entity Field Entity Type Risk Score
A suspicious powershell script with the ScriptBlockId [$ScriptBlockId$] containing stream commands to process compressed or decompressed binary file was executed on host $dest$ dest system 20

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation Passing N/A N/A N/A
Unit Passing Dataset XmlWinEventLog:Microsoft-Windows-PowerShell/Operational XmlWinEventLog
Integration ✅ Passing Dataset XmlWinEventLog:Microsoft-Windows-PowerShell/Operational XmlWinEventLog

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 19