WindowsT1216

>CL_Invocation.ps1

Aero diagnostics script

Default Executable Paths

C:\Windows\diagnostics\system\AERO\CL_Invocation.ps1
C:\Windows\diagnostics\system\Audio\CL_Invocation.ps1
C:\Windows\diagnostics\system\WindowsUpdate\CL_Invocation.ps1

Integrity & Metadata

Category Count: 1 weaponized patterns
Forensics & Triage Insight

Documented in LOLBAS project by Oddvar Moe.

Detection Engineering Notes

Monitor process creation events where FileName is "CL_Invocation.ps1" or command line references known attack arguments.

Executive Summary & AI Quick Reference

High-Fidelity Telemetry Profile

CL_Invocation.ps1 is a native utility pre-installed on Windows systems. Threat actors and red teams abuse CL_Invocation.ps1 as a Living-off-the-Land Binary (LOLBin) to achieve Execute without triggering traditional antivirus file-hash alerts. Legitimate system administrators use it for routine administration, making behavioral command-line telemetry essential for differentiation.

Primary Abused Tactics
Execute
Minimum Privilege
User
Key Telemetry Source
Sysmon 1 / 4688
ATT&CK Mapping
T1216

Weaponized Parameters & Proof-of-Concepts

Documented attack commands, parameter flags, and privilege prerequisites.

1 documented methods
Filter Purpose:
ExecutePrivileges: User
T1216: Technique T1216

Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.

. C:\Windows\diagnostics\system\AERO\CL_Invocation.ps1   \nSyncInvoke {CMD}

SIEM & EDR Detection Rules

Production telemetry rules configured for Microsoft Defender, Sigma, and Splunk.

Telemetry & SIEM Detection Suite (CL_Invocation.ps1)

Validated against MITRE T1216
CL_Invocation.ps1 Microsoft Defender Querykql
1// Microsoft Defender XDR / Microsoft Sentinel
2// Tactic: Execute
3DeviceProcessEvents
4| where FileName =~ "CL_Invocation.ps1"
5| where ProcessCommandLine has_any ("CL_Invocation.ps1")
6| project
7 Timestamp,
8 DeviceName,
9 AccountName,
10 InitiatingProcessParentFileName,
11 InitiatingProcessFileName,
12 InitiatingProcessCommandLine,
13 FileName,
14 FolderPath,
15 ProcessCommandLine,
16 MD5,
17 SHA256
18| sort by Timestamp desc

Mitigation, Hardening & Prevention

Recommended defensive controls to block or constrain CL_Invocation.ps1 abuse.

Application Whitelisting

Enforce Windows Defender Application Control (WDAC) or AppLocker publisher rules to prevent execution outside approved enterprise administration scripts.

Attack Surface Reduction

Enable ASR rules: Block executable content from email client and webmail and Block Office applications from creating child processes spawning CL_Invocation.ps1.

Behavioral Alerting

Deploy the KQL, Sigma, and Splunk detection queries below. Alert on anomalous child processes, web requests to unrated external IPs, or encoded payload strings.

Frequently Asked Questions (FAQ) • CL_Invocation.ps1

Key operational questions and defensive answers about CL_Invocation.ps1 LOLBin tradecraft.

What is CL_Invocation.ps1 and why is it classified as a LOLBin?

CL_Invocation.ps1 is a legitimate, pre-installed or trusted utility on Windows. It is classified as a Living-off-the-Land Binary (LOLBin) because adversaries abuse its built-in functionality to perform malicious operations—such as Execute—without dropping custom malware binaries on disk.

How do threat actors abuse CL_Invocation.ps1 in cyber intrusions?

Adversaries leverage CL_Invocation.ps1 to execute stealthy actions while evading signature-based security controls. For example, attackers execute commands like ". C:\Windows\diagnostics\system\AERO\CL_Invocation.ps1 \nSyncInvoke {CMD}" to achieve Execute, masquerading behind legitimate system process lineage.

How can SOC analysts detect suspicious CL_Invocation.ps1 activity?

Detection engineers monitor process creation events (Windows Event ID 4688 or Sysmon Event ID 1; Linux auditd EXECVE; macOS Endpoint Security) inspecting anomalous command line arguments, unusual parent-child process relationships (e.g. Office apps or web servers spawning CL_Invocation.ps1), and unexpected network connections.

What MITRE ATT&CK techniques does CL_Invocation.ps1 map to?

CL_Invocation.ps1 maps to MITRE ATT&CK technique(s): T1216. These techniques cover adversary actions across tactics such as Defense Evasion, Execution, Persistence, and Command and Control.

How can organizations mitigate and restrict CL_Invocation.ps1?

Mitigation strategies include implementing Application Control policies (AppLocker or Windows Defender Application Control - WDAC), enforcing Attack Surface Reduction (ASR) rules, configuring strict privilege separation (disallowing standard users from running sensitive switches), and alerting on execution from non-standard directories.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point