Rule Info
Name
PowerShell Script Execution From Environment Variable - CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell loading and executing a script stored inside an environment variable.
Attackers use this to hide the malicious code from command-line logs and security tools,
since the actual script is never written to disk or shown in the process arguments.
Reference
Date
2026-09-08 00:00:00
Modified
None
Id
6b5492fd-8fa5-408c-b467-f309d015efca
Tags
attack.execution attack.t1059.001 attack.stealth attack.t1027.010
Type
Nextron Sigma feed only (private)
