PowerShell Logging Disabled Via Registry Key Tampering

 Original Source: [Sigma source]
Title: PowerShell Logging Disabled Via Registry Key Tampering
Status: test
Description:Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-32---windows-powershell-logging-disabled
Author: frack113
Date: 2022-04-02
modified:2023-08-17
Tags:
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1564.001'
  • -'attack.t1112'
  • -'attack.persistence'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains:
      -'\Microsoft\Windows\PowerShell\'
      -'\Microsoft\PowerShellCore\'

    TargetObject|endswith:
      -'\ModuleLogging\EnableModuleLogging'
      -'\ScriptBlockLogging\EnableScriptBlockLogging'
      -'\ScriptBlockLogging\EnableScriptBlockInvocationLogging'
      -'\Transcription\EnableTranscripting'
      -'\Transcription\EnableInvocationHeader'
      -'\EnableScripts'

    Details: 'DWORD (0x00000000)'
  condition:selection
Falsepositives:
  -Unknown
Level: high