This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Change PowerShell Policies to an Insecure Level - PowerShell
Original Source:
[Sigma source]
Title:
Change PowerShell Policies to an Insecure Level - PowerShell
Status:
test
Description:
Detects changing the PowerShell script execution policy to a potentially insecure level using the "Set-ExecutionPolicy" cmdlet.
References:
-https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.4
-https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies?view=powershell-7.4
-https://adsecurity.org/?p=2604
Author:
frack113
Date:
2021-10-20
modified:
2023-12-14
Tags:
-'attack.execution'
-'attack.t1059.001'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection_cmdlet:
ScriptBlockText|contains
:
'Set-ExecutionPolicy'
selection_option:
ScriptBlockText|contains
:
-'Unrestricted'
-'bypass'
filter_optional_chocolatey:
ScriptBlockText|contains
:
-'(New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1')'
-'(New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1')'
condition
:
all of selection_* and not 1 of filter_optional_*
Falsepositives:
-Administrator script
Level:
medium