IIS New Module Installation via Powershell

Rule Info

Name
IIS New Module Installation via Powershell
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of PowerShell cmdlet New-WebGlobalModule to install new IIS (Internet Information Services) global modules. This technique could be used by attackers to install unauthorized modules in IIS, enabling traffic interception or persistence. Monitoring this cmdlet is important as it represent less common ways to install new IIS module, than a normal way via appcmd.exe.
Date
2025-05-06 00:00:00
Modified
None
Id
539cff4c-251d-41be-8e4a-96963c36215f
Tags
attack.persistence attack.t1505.004
Type
Nextron Sigma feed only (private)

Rule History