| ID | Technique | Tactic |
|---|---|---|
| T1059.001 | PowerShell | Execution |
Detection: Powershell Processing Stream Of Data
Description
The following analytic detects suspicious PowerShell script execution involving compressed stream data processing, identified via EventCode 4104.
It leverages PowerShell Script Block Logging to flag scripts using IO.Compression, IO.StreamReader, or decompression methods.
This activity is significant as it often indicates obfuscated PowerShell or embedded .NET/binary execution, which are common tactics for evading detection.
If confirmed malicious, this behavior could allow attackers to execute hidden code, escalate privileges, or maintain persistence within the environment.
Search
1`powershell`
2EventCode=4104
3ScriptBlockText IN (
4 "*IO.Compression.*",
5 "*IO.StreamReader*",
6 "*]::Decompress*"
7)
8
9| fillnull
10
11| stats count min(_time) as firstTime
12 max(_time) as lastTime
13 by dest signature signature_id
14 user_id vendor_product EventID
15 Guid Opcode Name
16 Path ProcessID ScriptBlockId
17 ScriptBlockText
18
19| `security_content_ctime(firstTime)`
20
21| `security_content_ctime(lastTime)`
22
23| `powershell_processing_stream_of_data_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Powershell Script Block Logging 4104 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-PowerShell/Operational' |
Macros Used
| Name | Value |
|---|---|
| powershell | (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational" OR source=WinEventLog:PowerShellCore/Operational OR source="XmlWinEventLog:PowerShellCore/Operational") |
| powershell_processing_stream_of_data_filter | search * |
powershell_processing_stream_of_data_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://help.splunk.com/en/security-offerings/splunk-user-behavior-analytics/get-data-in/5.4.1/add-other-data-to-splunk-uba/configure-powershell-logging-to-see-powershell-anomalies-in-splunk-uba.
Known False Positives
powershell may used this function to process compressed data.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| A suspicious powershell script with the ScriptBlockId [$ScriptBlockId$] containing stream commands to process compressed or decompressed binary file was executed on host $dest$ | dest | system | 20 |
References
-
https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
-
https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
-
https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-PowerShell/Operational |
XmlWinEventLog |
| Integration | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-PowerShell/Operational |
XmlWinEventLog |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 19