Rule Info
Name
PowerShell Dynamic Module Command Invocation via Index Access - PsScript
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell scripts that dynamically invoke commands from the Microsoft.PowerShell.Utility module using index access on the ExportedCommands collection.
Threat actors may use this technique to bypass detection mechanisms that look for specific command names, as the actual commands being invoked are determined at runtime and may not be explicitly mentioned in the script.
Date
2026-05-11 00:00:00
Modified
None
Id
a9c1d3e5-2f4b-6a7c-8d9e-0b1c2d3e4f5a
Tags
attack.execution attack.stealth attack.t1059.001 attack.t1027.010
Type
Nextron Sigma feed only (private)
