{"id":"5b40a734-99b6-4b98-a1d0-1cea51a08ab2","title":"Suspicious Interactive PowerShell as SYSTEM","description":"Detects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-12-07","modified":"2022-08-13","tags":["attack.execution","attack.t1059.001"],"technique_ids":["T1059.001"],"logsource":{"product":"windows","category":"file_event"},"falsepositives":["Administrative activity","PowerShell scripts running as SYSTEM user"],"references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/PowerSploit_Invoke-Mimikatz.htm"],"source_path":"rules/windows/file/file_event/file_event_win_susp_system_interactive_powershell.yml","source_sha256":"0536b14770e8c1ef3d5416b9a546f1efaadb6c54a2edf11efbe29a4823ccbb1a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_susp_system_interactive_powershell.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious Interactive PowerShell as SYSTEM\nid: 5b40a734-99b6-4b98-a1d0-1cea51a08ab2\nstatus: test\ndescription: Detects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context\nreferences:\n    - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/PowerSploit_Invoke-Mimikatz.htm\nauthor: Florian Roth (Nextron Systems)\ndate: 2021-12-07\nmodified: 2022-08-13\ntags:\n    - attack.execution\n    - attack.t1059.001\nlogsource:\n    product: windows\n    category: file_event\ndetection:\n    selection:\n        TargetFilename:\n            - 'C:\\Windows\\System32\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadLine\\ConsoleHost_history.txt'\n            - 'C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\PowerShell\\StartupProfileData-Interactive'\n    condition: selection\nfalsepositives:\n    - Administrative activity\n    - PowerShell scripts running as SYSTEM user\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1059.001","id":"T1059.001","name":"PowerShell","page":"techniques/enterprise/T1059.001/"}],"data_path":"data/detection-rules/5b40a734-99b6-4b98-a1d0-1cea51a08ab2.json","kind":"sigma"}
