Potential Startup Shortcut Persistence Via PowerShell.EXE

 Original Source: [Sigma source]
Title: Potential Startup Shortcut Persistence Via PowerShell.EXE
Status: test
Description:Detects PowerShell writing startup shortcuts. This procedure was highlighted in Red Canary Intel Insights Oct. 2021, "We frequently observe adversaries using PowerShell to write malicious .lnk files into the startup directory to establish persistence. Accordingly, this detection opportunity is likely to identify persistence mechanisms in multiple threats. In the context of Yellow Cockatoo, this persistence mechanism eventually launches the command-line script that leads to the installation of a malicious DLL"
References:
  -https://redcanary.com/blog/intelligence-insights-october-2021/
  -https://github.com/redcanaryco/atomic-red-team/blob/36d49de4c8b00bf36054294b4a1fcbab3917d7c5/atomics/T1547.001/T1547.001.md#atomic-test-7---add-executable-shortcut-link-to-user-startup-folder
Author: Christopher Peacock '@securepeacock', SCYTHE
Date: 2021-10-24
modified:2023-02-23
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    TargetFilename|contains: '\start menu\programs\startup\'
    TargetFilename|endswith: '.lnk'
  condition:selection
Falsepositives:
  -Depending on your environment accepted applications may leverage this at times. It is recommended to search for anomalies inidicative of malware.
Level: high