
Summary
Detects a PowerShell-based technique where an attacker enumerates the Microsoft.PowerShell.Utility module's ExportedCommands and then invokes a cmdlet indirectly by indexing into that array. The rule matches Windows PowerShell processes (powershell.exe or pwsh.exe) whose command line shows exploration of a loaded module via Get-Module (gmo), ListAvailable, Microsoft.PowerShell.Utility, and ExportedCommands/Values, followed by an indirect call using an array index (e.g., [*]). This evasion tactic hides explicit cmdlet names (such as Invoke-RestMethod or Invoke-Expression) and relies on dynamic invocation through the ExportedCommands array, making detection based on literal strings less reliable. The rule requires the presence of the PowerShell process image, and a command line that contains all of: Get-Module, ListAvailable, Microsoft.PowerShell.Utility, ExportedCommands, Values, and an index operation ([*]). False positives may occur during legitimate administrative activities that enumerate or reference module exported commands, though such usage is expected to be rare in practice. The rule is labeled high severity due to its stealthy nature and potential to bypass straightforward string-matching detections.
Categories
- Endpoint
- Windows
Data Sources
- Process
- Image
- Script
- Command
Created: 2026-10-06