Windows PowerShell Script Installs and Configures PowerShell Web Access (PSWA)

Detects PowerShell Web Access installation and web authorization configuration from Windows PowerShell script blocks.

FreeUnreviewedSigmahighv1
title: Windows PowerShell Script Installs and Configures PowerShell Web Access (PSWA)
id: ce0e85f5-dcd3-4158-ab75-039a44bf32ba
status: test
description: This rule flags PowerShell script activity that installs WindowsPowerShellWebAccess, creates a PSWA web application, and configures broad authorization rules. Attackers can use this to establish remote access through PowerShell Web Access for follow-on execution or abuse. The detection relies on Script Block Logging telemetry matching specific command strings within PowerShell ScriptBlockText.
references:
  - https://docs.microsoft.com/en-us/powershell/module/powershellwebaccess/install-pswawebapplication
  - https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
  - https://gist.github.com/MHaggis/7e67b659af9148fa593cf2402edebb41
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_powershell_web_access_installation.yml
author: Michael Haag, Huntrule Team
date: 2024-09-03
tags:
  - attack.persistence
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_install:
    ScriptBlockText|contains: Install-WindowsFeature WindowsPowerShellWebAccess
  selection_config:
    ScriptBlockText|contains: Install-PswaWebApplication
  selection_auth:
    ScriptBlockText|contains|all:
      - Add-PswaAuthorizationRule
      - -UserName *
      - -ComputerName *
  condition: 1 of selection_*
falsepositives:
  - Legitimate PowerShell Web Access installations by administrators
level: high
license: DRL-1.1
related:
  - id: 5f9c7f1a-7c21-4c39-b2f3-8d8006e0e51f
    type: derived

What it detects

This rule flags PowerShell script activity that installs WindowsPowerShellWebAccess, creates a PSWA web application, and configures broad authorization rules. Attackers can use this to establish remote access through PowerShell Web Access for follow-on execution or abuse. The detection relies on Script Block Logging telemetry matching specific command strings within PowerShell ScriptBlockText.

Known false positives

  • Legitimate PowerShell Web Access installations by administrators

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.