Change PowerShell Policies to an Insecure Level - PowerShell

 Original Source: [Sigma source]
Title: Change PowerShell Policies to an Insecure Level - PowerShell
Status: test
Description:Detects changing the PowerShell script execution policy to a potentially insecure level using the "Set-ExecutionPolicy" cmdlet.
References:
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.4
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies?view=powershell-7.4
  -https://adsecurity.org/?p=2604
Author: frack113
Date: 2021-10-20
modified:2023-12-14
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_cmdlet:
    ScriptBlockText|contains: 'Set-ExecutionPolicy'
  selection_option:
    ScriptBlockText|contains:
      -'Unrestricted'
      -'bypass'

  filter_optional_chocolatey:
    ScriptBlockText|contains:
      -'(New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1')'
      -'(New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1')'

  condition:all of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Administrator script
Level: medium