IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Is it Possible to Prevent Invoke-Command Powershell Attacks?

App Control: Is it Possible to Prevent Invoke-Command Powershell Attacks?

Environment

  • App Control (Formerly CB Protection) Console: All supported versions
     

Question

Is it possible to prevent Invoke-Command powershell attacks?

Answer

This article shows where the invoke-command can be blocked using a rapid config.

The CB Protection Powershell Rapid Config has been updated.

 


Additional Notes

  • This  rapid config can protect against powershell downgrade attacks which may be used to bypass other protections.
  • Exceptions can be made to facilitate good applications being able to execute.
  • The rapid config rule would be able to report or block powershell commands with the following argument:
    <CmdlineAnyArgument:iex>*
  • <cmdline:*iex*>* can also be used with wildcards to add additional detections
  • The rapid configs don't support Regex use

Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎10-13-2020
Views:
667