DSC (Desired State Configuration) lateral movement using PowerShell
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Lateral Movement (TA0008), Execution (TA0002)
ATT&CK Technique
Windows Management Instrumentation (T1047), Remote Services: Windows Remote Management (T1021.006)
Severity
Informational
Description
An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine.
Attacker's Goals
Execute malicious content on and move laterally across machine in the network.
Investigative actions
Search for suspicious WinRM sessions and the user created them, can be found at Event ID: 4102.
Additionally, search for the DSC resource executed and related IOC, can be found at Event IDs: 400 or 4104.
Variations
Was this helpful?
