Windows PowerShell Software Enumeration via Script Block Content

Flags PowerShell registry queries for installed software metadata combined with selection and table formatting.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
Nikita Nazarov, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-16
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies PowerShell script block activity that performs local software discovery by combining registry queries under a Windows software path with output formatting. Such enumeration can help an attacker determine installed products and versions to assess exposure and tailor follow-on activity. Telemetry relies on Script Block logging capturing the script text content for matching registry-related queries and PowerShell cmdlets.

Related detections3 linkedT1518 — drag to rearrange
Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Windows process command line matches WinPwn tool execution keywords
Windows Process: reg.exe Software Version Discovery via svcVersion Query
Windows PowerShell Software Enumeration via Script Block Content
Pivot detection · T1518 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.