Rule Info
Name
PowerShell Dynamic Module Command Invocation via Index Access
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell scripts that dynamically invoke commands from the Microsoft.PowerShell.Utility module using index access on the ExportedCommands collection.
Threat actors may use this technique to bypass detection mechanisms that look for specific command names, as the actual commands being invoked are determined at runtime and may not be explicitly mentioned in the script.
Date
2026-05-11 00:00:00
Modified
None
Id
f4b2e8a1-7c3d-4e5f-9a6b-1d2c3e4f5a6b
Tags
attack.execution attack.stealth attack.t1059.001 attack.t1027.010
Type
Nextron Sigma feed only (private)
