App Control: Is it Possible to Prevent Invoke-Command Powershell Attacks?
search cancel

App Control: Is it Possible to Prevent Invoke-Command Powershell Attacks?

book

Article ID: 287145

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Is it possible to prevent Invoke-Command powershell attacks?

Environment

  • App Control (Formerly CB Protection) Console: All supported versions
     

Resolution

This article shows where the invoke-command can be blocked using a rapid config.

https://community.carbonblack.com/t5/Documentation-Downloads/The-CB-Protection-Powershell-Rapid-Config-has-been-updated/ta-p/79488

 

Additional Information

  • This  rapid config can protect against powershell downgrade attacks which may be used to bypass other protections.
  • Exceptions can be made to facilitate good applications being able to execute.
  • The rapid config rule would be able to report or block powershell commands with the following argument:
    <CmdlineAnyArgument:iex>*
  • <cmdline:*iex*>* can also be used with wildcards to add additional detections
  • The rapid configs don't support Regex use