Detection rules › By event
PowerShell Event ID 800
Sigma (37)
- Active Directory Forest PowerShell class called from a non administrative host
- BITS payload downloaded via PowerShell
- DCOM lateral movement (via MMC20)
- Domain group membership change
- DoT (DNS over TLS) activation (PowerShell)
- DSRM password changed (Reg via PowerShell)
- Encoded PowerShell payload deployed (PowerShell)
- Event log clear attempt (PowerShell)
- Event log cleared using Diagnostics (via PowerShell)
- Exchange transport agent installation artifacts (PowerShell)
- Firewall configuration enumerated (PowerShell)
- Firewall deactivation (PowerShell)
- Group discovery (PowerShell)
- Local group membership change
- LSASS credential dump with LSASSY (PowerShell)
- Microsoft Defender critical security components disabled (PowerShell)
- Microsoft Defender default action changed to allow any threat (PowerShell)
- Microsoft Defender security components disabled (PowerShell)
- Microsoft Defender threat exclusion added (PowerShell)
- OpenSSH native server feature installation
- OpenSSH server firewall configuration on Windows (PowerShell)
- OpenSSH service activation on Windows
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes
- Print spooler privilege escalation via printer added (CVE-2020-1048)
- Service abuse with backdoored "command failure" (Reg via PowerShell)
- Service abuse with malicious ImagePath (Reg via PowerShell)
- Service creation (PowerShell)
- Service permissions hijacked for privileges abuse (PowerShell)
- Service permissions hijacked for privileges abuse (Reg via PowerShell)
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell)
- System time changed (PowerShell)
- Vault credentials manager accessed
- VSS backup deletion via WMI (Powershell)
- Webserver IIS module installed (PowerShell)
- Webserver IIS module installed via GAC manipulation (PowerShell)
- WMI registration (PowerShell)