Windows PowerShell Script Installs and Configures PowerShell Web Access (PSWA)
Detects PowerShell Web Access installation and web authorization configuration from Windows PowerShell script blocks.
FreeUnreviewedSigmahighv1
windows-powershell-script-installs-and-configures-powershell-web-access-pswa-5f9c7f1a
title: Windows PowerShell Script Installs and Configures PowerShell Web Access (PSWA)
id: ce0e85f5-dcd3-4158-ab75-039a44bf32ba
status: test
description: This rule flags PowerShell script activity that installs WindowsPowerShellWebAccess, creates a PSWA web application, and configures broad authorization rules. Attackers can use this to establish remote access through PowerShell Web Access for follow-on execution or abuse. The detection relies on Script Block Logging telemetry matching specific command strings within PowerShell ScriptBlockText.
references:
- https://docs.microsoft.com/en-us/powershell/module/powershellwebaccess/install-pswawebapplication
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
- https://gist.github.com/MHaggis/7e67b659af9148fa593cf2402edebb41
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_powershell_web_access_installation.yml
author: Michael Haag, Huntrule Team
date: 2024-09-03
tags:
- attack.persistence
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_install:
ScriptBlockText|contains: Install-WindowsFeature WindowsPowerShellWebAccess
selection_config:
ScriptBlockText|contains: Install-PswaWebApplication
selection_auth:
ScriptBlockText|contains|all:
- Add-PswaAuthorizationRule
- -UserName *
- -ComputerName *
condition: 1 of selection_*
falsepositives:
- Legitimate PowerShell Web Access installations by administrators
level: high
license: DRL-1.1
related:
- id: 5f9c7f1a-7c21-4c39-b2f3-8d8006e0e51f
type: derived
What it detects
This rule flags PowerShell script activity that installs WindowsPowerShellWebAccess, creates a PSWA web application, and configures broad authorization rules. Attackers can use this to establish remote access through PowerShell Web Access for follow-on execution or abuse. The detection relies on Script Block Logging telemetry matching specific command strings within PowerShell ScriptBlockText.
Known false positives
- Legitimate PowerShell Web Access installations by administrators
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.