PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-01-09
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process creations where the command line indicates PowerShell (powershell.exe/pwsh) and also references an AppData path. Attackers commonly use AppData to store and run scripts or payloads that blend into user-writable locations. The detection relies on Windows process creation telemetry, matching command-line substrings for PowerShell plus /c and AppData subpaths (Local\ and/or Roaming\).
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell Executed From AppData on Windows (Command Line Indicators)
id: 4d6fa429-50fb-4a07-b573-c47e57bec63d
status: test
description: This rule identifies process creations where the command line indicates PowerShell (powershell.exe/pwsh) and also references an AppData path. Attackers commonly use AppData to store and run scripts or payloads that blend into user-writable locations. The detection relies on Windows process creation telemetry, matching command-line substrings for PowerShell plus /c and AppData subpaths (Local\ and/or Roaming\).
references:
- https://twitter.com/JohnLaTwC/status/1082851155481288706
- https://app.any.run/tasks/f87f1c4e-47e2-4c46-9cf4-31454c06ce03
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_susp_ps_appdata.yml
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team
date: 2019-01-09
modified: 2022-07-14
tags:
- attack.execution
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection1:
CommandLine|contains:
- powershell.exe
- \powershell
- \pwsh
- pwsh.exe
selection2:
CommandLine|contains|all:
- "/c "
- \AppData\
CommandLine|contains:
- Local\
- Roaming\
condition: all of selection*
falsepositives:
- Administrative scripts
level: medium
license: DRL-1.1
related:
- id: ac175779-025a-4f12-98b0-acdaeb77ea85
type: derived