Skip to content

Write a Sigma Detection for Suspicious PowerShell

This walkthrough uses the Sigma CLI through uvx and the Splunk backend plugin. Install uv on the analysis workstation first; these commands run the CLI in a temporary environment and do not deploy a rule to a SIEM.

PowerShell is common in administration and in attacks, so a useful rule should identify suspicious command-line combinations and retain investigation context. This example targets process-creation events that show encoded execution or a hidden, non-interactive launch.

Test detections with benign lab commands and your SIEM’s field mapping. Sigma is a portable detection description; your backend converter and event pipeline determine the final query and available fields.


01

Verify the Event Source and Command-Line Fields

Telemetry

Confirm Sysmon Process Create (Event ID 1) or Windows Security event 4688 is collected with process and command-line fields. Ensure your Sigma log source matches that event pipeline.

Required fields:
Image / NewProcessName
CommandLine / ProcessCommandLine
ParentImage (useful for triage)
User and host identity
❯ View Expected Console Output
Telemetry check: process image and command line are populated.
Code editor displaying a Sigma process-creation rule for encoded or hidden PowerShell with YAML syntax highlighting

Figure 1: Keep the rule readable and validate its log source and selection logic.


02

Match PowerShell with Suspicious Command-Line Options

Sigma Rule

Save the rule as rules/suspicious-powershell.yml and assign a unique UUID. It requires PowerShell plus an encoded-command indicator or a hidden, non-interactive combination. Review variations such as pwsh.exe and your command-line normalization.

title: Suspicious PowerShell Encoded or Hidden Launch
id: 7a4e9207-9c3d-4c66-bac1-4d349e14c501
status: test
description: Detect PowerShell creation with encoded or hidden non-interactive options.
logsource:
category: process_creation
product: windows
detection:
selection_image:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
selection_encoded:
CommandLine|contains:
- ' -enc '
- ' -encodedcommand '
selection_hidden:
CommandLine|contains|all:
- ' -w hidden'
- ' -nop'
condition: selection_image and (selection_encoded or selection_hidden)
falsepositives:
- Approved automation that launches encoded PowerShell commands
level: medium
❯ View Expected Console Output
Rule parses as YAML.
Condition: PowerShell image AND (encoded OR hidden and no-profile options)

03

Inspect the Generated Query

Rule Validation

Run Sigma’s rule checker and convert the rule with the Splunk Windows pipeline. uvx fetches the CLI and backend plugin for each command. Confirm the result maps process image and command-line fields correctly and keeps the condition grouping intact; conversion does not deploy a detection.

Terminal window
uvx --from sigma-cli --with pysigma-backend-splunk sigma check --fail-on-error rules/suspicious-powershell.yml
uvx --from sigma-cli --with pysigma-backend-splunk sigma convert --target splunk --pipeline splunk_windows rules/suspicious-powershell.yml
❯ View Expected Console Output
Validation: rule passes with no errors
Conversion completed for the Splunk Windows pipeline.

04

Compare Matches with Approved Administrative Activity

Detection Tuning

Test with benign lab events and approved automation. Keep exclusions narrow and retain host, user, parent process, and full command line for triage.

Rule parses and converts for the production backend
Expected lab events match
Administrative baseline reviewed
Owner, severity, and response guidance assigned
❯ View Expected Console Output
Status after validation: test
Promote only after the detection owner approves tuning.

Comments