LoFP LoFP / powershell scripts running as system user

Techniques

Sample rules

Suspicious Interactive PowerShell as SYSTEM

Description

Detects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context

Detection logic

condition: selection
selection:
  TargetFilename:
  - C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
  - C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive