PowerShell as a Service in Registry

 Original Source: [Sigma source]
Title: PowerShell as a Service in Registry
Status: test
Description:Detects that a powershell code is written to the registry as a service.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
Author: oscd.community, Natalia Shornikova
Date: 2020-10-06
modified:2023-08-17
Tags:
  • -'attack.execution'
  • -'attack.t1569.002'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Services\'
    TargetObject|endswith: '\ImagePath'
    Details|contains:
      -'powershell'
      -'pwsh'

  condition:selection
Falsepositives:
  -Unknown
Level: high