37 detection rules reference this event. View event page.Sigma (37)
- Active Directory Forest PowerShell class called from a non administrative host severity medium T1482
- BITS payload downloaded via PowerShell severity medium T1048, T1105, T1197, T1570
- DCOM lateral movement (via MMC20) severity high T1021, T1021.003
- Domain group membership change severity high T1098
- DoT (DNS over TLS) activation (PowerShell) severity medium T1071, T1071.004
- DSRM password changed (Reg via PowerShell) severity high T1098
- Encoded PowerShell payload deployed (PowerShell) severity high T1027, T1059, T1059.001
- Event log clear attempt (PowerShell) severity high T1070, T1685.005
- Event log cleared using Diagnostics (via PowerShell) severity high T1070, T1685.005
- Exchange transport agent installation artifacts (PowerShell) severity high T1505, T1505.002
- Firewall configuration enumerated (PowerShell) severity medium T1016
- Firewall deactivation (PowerShell) severity high T1685, T1686
- Group discovery (PowerShell) severity medium T1069, T1069.001, T1069.002
- Local group membership change severity high T1098
- LSASS credential dump with LSASSY (PowerShell) severity medium T1003, T1003.001
- Microsoft Defender critical security components disabled (PowerShell) severity high T1685
- Microsoft Defender default action changed to allow any threat (PowerShell) severity high T1685
- Microsoft Defender security components disabled (PowerShell) severity medium T1685
- Microsoft Defender threat exclusion added (PowerShell) severity high T1685
- OpenSSH native server feature installation severity medium T1021, T1021.004
- OpenSSH server firewall configuration on Windows (PowerShell) severity high T1685, T1686
- OpenSSH service activation on Windows severity medium T1021, T1021.004
- Payload downloaded via PowerShell severity high T1059, T1059.001, T1105
- PipeShell exfiltration over named pipes severity medium T1059, T1059.001
- Print spooler privilege escalation via printer added (CVE-2020-1048) severity high T1547, T1547.010
- Service abuse with backdoored "command failure" (Reg via PowerShell) severity high T1543, T1543.003
- Service abuse with malicious ImagePath (Reg via PowerShell) severity high T1543, T1543.003
- Service creation (PowerShell) severity high T1543, T1543.003
- Service permissions hijacked for privileges abuse (PowerShell) severity high T1543, T1543.003, T1574, T1574.010
- Service permissions hijacked for privileges abuse (Reg via PowerShell) severity high T1543, T1543.003, T1574, T1574.010
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell) severity high T1087, T1087.002, T1558, T1558.003
- System time changed (PowerShell) severity medium T1070, T1070.006
- Vault credentials manager accessed severity high T1555, T1555.004
- VSS backup deletion via WMI (Powershell) severity high T1490
- Webserver IIS module installed (PowerShell) severity high T1505, T1505.004
- Webserver IIS module installed via GAC manipulation (PowerShell) severity high T1505, T1505.004
- WMI registration (PowerShell) severity high T1546, T1546.003