Change PowerShell Policies to an Insecure Level
Description
Detects changing the PowerShell script execution policy to a potentially insecure level using the "-ExecutionPolicy" flag.
Query · sigma
selection_img: - OriginalFileName: - powershell_ise.exe - PowerShell.EXE - pwsh.dll - Image|endswith: - \powershell_ise.exe - \powershell.exe - \pwsh.exe selection_option: CommandLine|contains: - '-executionpolicy ' - ' -ep ' - ' -exec ' selection_level: CommandLine|contains: - Bypass - Unrestricted filter_main_powershell_core: ParentImage: - C:\Windows\SysWOW64\msiexec.exe - C:\Windows\System32\msiexec.exe CommandLine|contains: - -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\PowerShell\7\ - -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\PowerShell\7\ filter_optional_avast: ParentImage|contains: - C:\Program Files\Avast Software\Avast\ - C:\Program Files (x86)\Avast Software\Avast\ - \instup.exe CommandLine|contains: - -ExecutionPolicy ByPass -File "C:\Program Files\Avast Software\Avast - -ExecutionPolicy ByPass -File "C:\Program Files (x86)\Avast Software\Avast\ condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Administrator scripts