Suspicious Interactive PowerShell as SYSTEM
Description
Detects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context
Query · sigma
selection: TargetFilename: - C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt - C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive condition: selection
Known false positives
- Administrative activity
- PowerShell scripts running as SYSTEM user