PowerShell Profile Modification

 Original Source: [Sigma source]
Title: PowerShell Profile Modification
Status: test
Description:Detects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
References:
  -https://www.welivesecurity.com/2019/05/29/turla-powershell-usage/
  -https://persistence-info.github.io/Data/powershellprofile.html
Author: HieuTT35, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-10-24
modified:2023-10-23
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1546.013'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -'\Microsoft.PowerShell_profile.ps1'
      -'\PowerShell\profile.ps1'
      -'\Program Files\PowerShell\7-preview\profile.ps1'
      -'\Program Files\PowerShell\7\profile.ps1'
      -'\Windows\System32\WindowsPowerShell\v1.0\profile.ps1'
      -'\WindowsPowerShell\profile.ps1'

  condition:selection
Falsepositives:
  -System administrator creating Powershell profile manually
Level: medium