Potential PowerShell Console History Access Attempt via History File

 Original Source: [Sigma source]
Title: Potential PowerShell Console History Access Attempt via History File
Status: experimental
Description:Detects potential access attempts to the PowerShell console history directly via history file (ConsoleHost_history.txt). This can give access to plaintext passwords used in PowerShell commands or used for general reconnaissance.
References:
  -https://0xdf.gitlab.io/2018/11/08/powershell-history-file.html
Author: Luc Génaux
Date: 2025-04-03
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'ConsoleHost_history.txt'
      -'(Get-PSReadLineOption).HistorySavePath'

  condition:selection
Falsepositives:
  -Legitimate access of the console history file is possible
Level: medium