heroui logo

PowerShell Dynamic Module Invocation Via ExportedCommands Array Index - PS Script

Sigma Rules

View Source
Summary
Detects obfuscated PowerShell scripts that enumerate Microsoft.PowerShell.Utility exported commands and invoke cmdlets indirectly via array indexing. The rule targets scripts that enumerate module exports (Get-Module or its alias gmo) for Microsoft.PowerShell.Utility, then access the ExportedCommands.Values collection and invoke a command by indexing into the array (e.g., using [*]). This evasion technique hides explicit cmdlet names from simple string-based detections (e.g., Invoke-RestMethod or Invoke-Expression) by performing dynamic invocation through array indices. The rule requires Script Block Logging to be enabled and uses a two-part condition: (1) ScriptBlockText contains Get-Module (or gmo) and references Microsoft.PowerShell.Utility with ExportedCommands and Values, and (2) ScriptBlockText contains an indexing pattern like [*]. The rule is labeled experimental with a medium detection level and includes a false positives note for legitimate use where scripting may enumerate and invoke exported commands dynamically. It should be validated with regression data and in environments that have Script Block Logging enabled to reduce noise from benign scripts.
Categories
  • Windows
  • Endpoint
Data Sources
  • Script
Created: 2026-10-06