Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile

Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-24
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies creation or modification of the VSCode PowerShell profile file named Microsoft.VSCode_profile.ps1 on Windows. Attackers can use PowerShell profiles to execute commands automatically in interactive sessions, enabling persistence or follow-on actions. The rule relies on Windows file event telemetry that records changes to the target filename ending with \Microsoft.VSCode_profile.ps1.

Related detections3 linkedT1546.013 — drag to rearrange
Suspicious Creation of PowerShell Profile Script for Persistence
Windows PowerShell: Add-Content to $profile for Potential Persistence
Windows PowerShell Profile File Creation or Modification
Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Pivot detection · T1546.013 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.