Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted
Alerts on PowerShell started with -ExecutionPolicy set to Bypass/Unrestricted, indicating a potentially insecure script execution posture.
- Product
- windows
- Category
- process_creation
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-11-01
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where PowerShell (PowerShell.exe, pwsh.exe, or PowerShell ISE) is launched with execution policy arguments indicating an insecure state such as -ExecutionPolicy Bypass or Unrestricted. Attackers may use this to weaken script execution restrictions and run malicious or unsigned PowerShell content. The detection relies on process creation telemetry, matching PowerShell-related image names and specific command-line substrings containing execution policy values.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.4
- learn.microsoft.comhttps://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies?view=powershell-7.4
- adsecurity.orghttps://adsecurity.org/?p=2604
- thedfirreport.comhttps://thedfirreport.com/2021/11/01/from-zero-to-domain-admin/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted"
id: fa7aa8ea-8851-413d-b65f-4b3a44afcfe7
related:
- id: cf2e938e-9a3e-4fe8-a347-411642b28a9f
type: similar
- id: 61d0475c-173f-4844-86f7-f3eebae1c66b
type: similar
- id: fad91067-08c5-4d1a-8d8c-d96a21b37814
type: similar
- id: 87e3c4e8-a6a8-4ad9-bb4f-46e7ff99a180
type: derived
status: test
description: This rule flags Windows process creation events where PowerShell (PowerShell.exe, pwsh.exe, or PowerShell ISE) is launched with execution policy arguments indicating an insecure state such as -ExecutionPolicy Bypass or Unrestricted. Attackers may use this to weaken script execution restrictions and run malicious or unsigned PowerShell content. The detection relies on process creation telemetry, matching PowerShell-related image names and specific command-line substrings containing execution policy values.
references:
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.4
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies?view=powershell-7.4
- https://adsecurity.org/?p=2604
- https://thedfirreport.com/2021/11/01/from-zero-to-domain-admin/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level.yml
author: frack113, Huntrule Team
date: 2021-11-01
modified: 2025-10-07
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: process_creation
detection:
selection_img:
- OriginalFileName:
- powershell_ise.exe
- PowerShell.EXE
- pwsh.dll
- Image|endswith:
- \powershell_ise.exe
- \powershell.exe
- \pwsh.exe
selection_option:
CommandLine|contains:
- "-executionpolicy "
- " -ep "
- " -exec "
selection_level:
CommandLine|contains:
- Bypass
- Unrestricted
filter_main_powershell_core:
ParentImage:
- C:\Windows\SysWOW64\msiexec.exe
- C:\Windows\System32\msiexec.exe
CommandLine|contains:
- -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\PowerShell\7\
- -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\PowerShell\7\
filter_optional_avast:
ParentImage|contains:
- C:\Program Files\Avast Software\Avast\
- C:\Program Files (x86)\Avast Software\Avast\
- \instup.exe
CommandLine|contains:
- -ExecutionPolicy ByPass -File "C:\Program Files\Avast Software\Avast
- -ExecutionPolicy ByPass -File "C:\Program Files (x86)\Avast Software\Avast\
condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Administrator scripts
level: medium
license: DRL-1.1