Write a Sigma Detection for Suspicious PowerShell
This walkthrough uses the Sigma CLI through uvx and the Splunk backend plugin. Install uv on the analysis workstation first; these commands run the CLI in a temporary environment and do not deploy a rule to a SIEM.
PowerShell is common in administration and in attacks, so a useful rule should identify suspicious command-line combinations and retain investigation context. This example targets process-creation events that show encoded execution or a hidden, non-interactive launch.
Test detections with benign lab commands and your SIEM’s field mapping. Sigma is a portable detection description; your backend converter and event pipeline determine the final query and available fields.
Verify the Event Source and Command-Line Fields
TelemetryConfirm Sysmon Process Create (Event ID 1) or Windows Security event 4688 is collected with process and command-line fields. Ensure your Sigma log source matches that event pipeline.
Required fields:Image / NewProcessNameCommandLine / ProcessCommandLineParentImage (useful for triage)User and host identity❯ View Expected Console Output
Telemetry check: process image and command line are populated.
Figure 1: Keep the rule readable and validate its log source and selection logic.
Match PowerShell with Suspicious Command-Line Options
Sigma RuleSave the rule as rules/suspicious-powershell.yml and assign a unique UUID. It requires PowerShell plus an encoded-command indicator or a hidden, non-interactive combination. Review variations such as pwsh.exe and your command-line normalization.
title: Suspicious PowerShell Encoded or Hidden Launchid: 7a4e9207-9c3d-4c66-bac1-4d349e14c501status: testdescription: Detect PowerShell creation with encoded or hidden non-interactive options.logsource: category: process_creation product: windowsdetection: selection_image: Image|endswith: - '\powershell.exe' - '\pwsh.exe' selection_encoded: CommandLine|contains: - ' -enc ' - ' -encodedcommand ' selection_hidden: CommandLine|contains|all: - ' -w hidden' - ' -nop' condition: selection_image and (selection_encoded or selection_hidden)falsepositives: - Approved automation that launches encoded PowerShell commandslevel: medium❯ View Expected Console Output
Rule parses as YAML.Condition: PowerShell image AND (encoded OR hidden and no-profile options)Inspect the Generated Query
Rule ValidationRun Sigma’s rule checker and convert the rule with the Splunk Windows pipeline. uvx fetches the CLI and backend plugin for each command. Confirm the result maps process image and command-line fields correctly and keeps the condition grouping intact; conversion does not deploy a detection.
uvx --from sigma-cli --with pysigma-backend-splunk sigma check --fail-on-error rules/suspicious-powershell.ymluvx --from sigma-cli --with pysigma-backend-splunk sigma convert --target splunk --pipeline splunk_windows rules/suspicious-powershell.yml❯ View Expected Console Output
Validation: rule passes with no errorsConversion completed for the Splunk Windows pipeline.Compare Matches with Approved Administrative Activity
Detection TuningTest with benign lab events and approved automation. Keep exclusions narrow and retain host, user, parent process, and full command line for triage.
Rule parses and converts for the production backendExpected lab events matchAdministrative baseline reviewedOwner, severity, and response guidance assigned❯ View Expected Console Output
Status after validation: testPromote only after the detection owner approves tuning.