Detectionlowtest

PowerShell Script Execution Policy Enabled

Detects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.

Convert In Phoenix Studio

Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.

Launch
Nasreddine Bencherchali (Nextron Systems), Thurein OoCreated Wed Oct 188218c875-90b9-42e2-b60d-0b0069816d10windows
Log Source
WindowsRegistry Set
ProductWindows← raw: windows
CategoryRegistry Set← raw: registry_set
Detection Logic
Detection Logic1 selector
detection:
    selection:
        TargetObject|endswith: '\Policies\Microsoft\Windows\PowerShell\EnableScripts'
        Details: 'DWORD (0x00000001)'
    condition: selection
False Positives

Likely

MITRE ATT&CK
Rule Metadata
Rule ID
8218c875-90b9-42e2-b60d-0b0069816d10
Status
test
Level
low
Type
Detection
Created
Wed Oct 18
Path
rules/windows/registry/registry_set/registry_set_powershell_enablescripts_enabled.yml
Raw Tags
attack.execution
View on GitHub