Potential Persistence Via PowerShell User Profile Using Add-Content

 Original Source: [Sigma source]
Title: Potential Persistence Via PowerShell User Profile Using Add-Content
Status: test
Description:Detects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.013/T1546.013.md
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-08-18
modified:2023-05-04
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1546.013'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_add:
    ScriptBlockText|contains: 'Add-Content $profile'
  selection_options:
    ScriptBlockText|contains:
      -'-Value "IEX '
      -'-Value "Invoke-Expression'
      -'-Value "Invoke-WebRequest'
      -'-Value "Start-Process'
      -'-Value 'IEX '
      -'-Value 'Invoke-Expression'
      -'-Value 'Invoke-WebRequest'
      -'-Value 'Start-Process'

  condition:all of selection_*
Falsepositives:
  -Legitimate administration and tuning scripts that aim to add functionality to a user PowerShell session
Level: medium