Suspicious PowerShell Execution Bypass Running Script From ProgramData

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell launched with an execution policy bypass to run a script stored in C\ProgramData, matching the ToddyCat loader that executed c\programdata\ip445.ps1. Staging scripts in the world-accessible ProgramData directory and bypassing execution policy is a common tradecraft for running attacker tooling with minimal friction. The combination is unusual for legitimate administrative scripts.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious cmd.exe Launching Encoded PowerShell From Shortcut File
Suspicious Cursor Editor Process Spawning PowerShell
Suspicious PowerShell Base64 Encoded Staged Downloader via process_creation
Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious PowerShell Version Pinning with Encoded Command
Suspicious Encoded PowerShell Spawned from Explorer via ClickFix
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
PowerShell ExportedCommands Array Index for Indirect Cmdlet Execution (Windows Process Creation)
Suspicious PowerShell Execution Bypass Running Script From ProgramData
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.