Windows Registry Key Changes Disabling PowerShell Logging for Current User

Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-04-02
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry modifications for the currently logged-in user that set PowerShell logging-related values to DWORD 0x00000000. Attackers may disable module logging, script block logging, transcription, or script execution logging to reduce visibility and hinder detection. It relies on registry set telemetry that records changes to TargetObject paths under Microsoft\Windows\PowerShell and Microsoft\PowerShellCore, specifically matching logging configuration keys and a zero DWORD value.

Related detections9 linkedT1112 — drag to rearrange
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Suspicious Loopback Proxy Server Configured via Registry (via registry_set)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Suspicious Executable Written to User Documents Subfolder (via file_event)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious Sobolan Staging Directory Creation in var tmp (via file_event)
Malicious Gh0stBins RAT Registry Marker HHClient
Windows Registry Key Changes Disabling PowerShell Logging for Current User
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.