Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents

Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements) (SigmaHQ), DRL 1.1
Published
2019-09-12
Updated
2026-07-30
title: "Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents"
id: 9a4aab2c-9c25-4742-a9f8-d2ee0038f8db
status: test
description: This rule flags process creation where the executable ends with powershell.exe or pwsh.exe (including specific original file name variants) and the parent process is not one of the excluded update-related or optional development/defense tooling parents. It is useful because PowerShell launched from unexpected non-interactive parents can indicate automated execution patterns commonly used during attacker tradecraft. The detection relies on Windows process creation telemetry including Image and ParentImage (and, for some optional exclusions, ParentCommandLine).
references:
  - https://web.archive.org/web/20200925032237/https://threathunterplaybook.com/notebooks/windows/02_execution/WIN-190410151110.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_non_interactive_execution.yml
author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule Team
date: 2019-09-12
modified: 2025-02-28
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
  filter_main_generic:
    ParentImage|endswith:
      - :\Windows\explorer.exe
      - :\Windows\System32\CompatTelRunner.exe
      - :\Windows\SysWOW64\explorer.exe
  filter_main_windows_update:
    ParentImage: :\$WINDOWS.~BT\Sources\SetupHost.exe
  filter_optional_vscode:
    ParentImage|endswith: \AppData\Local\Programs\Microsoft VS Code\Code.exe
    ParentCommandLine|contains: " --ms-enable-electron-run-as-node "
  filter_optional_terminal:
    ParentImage|contains: :\Program Files\WindowsApps\Microsoft.WindowsTerminal_
    ParentImage|endswith: \WindowsTerminal.exe
  filter_optional_defender:
    ParentImage|endswith: :\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Likely. Many admin scripts and tools leverage PowerShell in their BAT or VB scripts which may trigger this rule often. It is best to add additional filters or use this to hunt for anomalies
level: low
license: DRL-1.1
related:
  - id: f4bbd493-b796-416e-bbf2-121235348529
    type: derived