Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0451 — Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification
DET0451

Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1245 Analytic 1245
Windows

Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell Execution of PowerShell without -NoProfile flag
[ProfilePathList] Custom PowerShell host profiles or redirection to alternate profile paths
[ExecutionContext] Whether profile execution occurs under elevated user (e.g., Administrator, SYSTEM)
[ModuleOrScriptName] Specific modules or external programs loaded within profile
[TimeWindow] Correlation time between profile modification and PowerShell process start

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0451
STIX ID
x-mitre-detection-strategy--f31ad178-1f54-41a6-b286-8040e7eb7158
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.