PowerShell Profile

T1546.013

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (profile.ps1) is a script that runs when PowerShell starts and can be used as a logon script to customize user environments.

PowerShell supports several profiles depending on the user or host program. For example, there can be different profiles for PowerShell host programs such as the PowerShell console, PowerShell ISE or Visual Studio Code. An administrator can also configure a profile that applies to all users and host programs on the local computer.

Adversaries may modify these profiles to include arbitrary commands, functions, modules, and/or PowerShell drives to gain persistence. Every time a user opens a PowerShell session the modified script will be executed unless the -NoProfile flag is used when it is launched.

An adversary may also be able to escalate privileges if a script in a PowerShell profile is loaded and executed by an account with higher privileges, such as a domain administrator.

Detection rules3

Rules on DetectionCode tagged with T1546.013.

Sigma3

RuleLevelLog source
Potential Persistence Via PowerShell User Profile Using Add-Contentmediumwindows / ps_script
PowerShell Profile Modificationmediumwindows / file_event
VsCode Powershell Profile Modificationmediumwindows / file_event

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupTurla

Turla has used PowerShell profiles to maintain persistence on an infected machine.

References3

  1. ESET Turla PowerShell May 2019 Open source
    Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.
  2. Microsoft About Profiles Open source
    Microsoft. (2017, November 29). About Profiles. Retrieved June 14, 2019.
  3. Wits End and Shady PowerShell Profiles Open source
    DeRyke, A.. (2019, June 7). Lab Notes: Persistence and Privilege Elevation using the Powershell Profile. Retrieved July 8, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.