PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging

Identifies PowerShell script blocks querying sensitive registry keys tied to services and Run/Explorer/winlogon locations.

FreeReviewedSigma · Medium · v5
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-07-02
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags PowerShell script block content that references Windows registry paths commonly associated with service configuration and auto-start/run locations. Attackers often query these locations to discover how the system is configured and what software or persistence mechanisms may be present. It relies on Script Block Logging telemetry from Windows PowerShell to inspect the script text for registry path patterns.

Related detections9 linkedT1007 — drag to rearrange
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Windows reg.exe Registry Query Reconnaissance (Process Creation)
Registry Query for WDigest
Suspicious Installed Software Enumeration via Registry Uninstall Key Query
Windows WMI StdRegProv Registry Enumeration via wmic.exe
Linux Process Execution of esxcli Network Commands for ESXi Network Discovery
Linux Process Execution of esxcli VM Listing Commands
Linux ESXi esxcli VSAN Information Discovery via esxcli Command
Linux Process Creation: ESXi esxcli system discovery via system namespace
PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Pivot detection · T1007 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.