Windows Registry Run Key Entries Containing PowerShell Execution Strings
Alerts when registry Run key value data contains PowerShell launch or encoded download/execution strings on Windows.
- Product
- windows
- Category
- registry_set
- Author
- frack113, Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-03-17
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows registry entries in common auto-start Run locations when the value data contains PowerShell-related execution patterns (e.g., powershell/pwsh, encoded command usage, hidden/no-profile execution, web download and in-memory execution indicators, and ExecutionPolicy Bypass). Attackers often abuse Run keys to persist after login by storing commands or scripts that launch PowerShell on startup. The detection relies on registry_set telemetry capturing the TargetObject path and the value Details text to match these PowerShell indicators.
Reporting behind it
- github.comhttps://github.com/frack113/atomic-red-team/blob/a9051c38de8a5320b31c7039efcbd3b56cf2d65a/atomics/T1547.001/T1547.001.md#atomic-test-9---systembc-malware-as-a-service-registry
- trendmicro.comhttps://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
- github.comhttps://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_powershell_in_run_keys.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Run Key Entries Containing PowerShell Execution Strings
id: f6fe0851-fb98-446d-8539-f0ba7e97cdd9
status: test
description: This rule flags Windows registry entries in common auto-start Run locations when the value data contains PowerShell-related execution patterns (e.g., powershell/pwsh, encoded command usage, hidden/no-profile execution, web download and in-memory execution indicators, and ExecutionPolicy Bypass). Attackers often abuse Run keys to persist after login by storing commands or scripts that launch PowerShell on startup. The detection relies on registry_set telemetry capturing the TargetObject path and the value Details text to match these PowerShell indicators.
references:
- https://github.com/frack113/atomic-red-team/blob/a9051c38de8a5320b31c7039efcbd3b56cf2d65a/atomics/T1547.001/T1547.001.md#atomic-test-9---systembc-malware-as-a-service-registry
- https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
- https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_powershell_in_run_keys.yml
author: frack113, Florian Roth (Nextron Systems), Huntrule Team
date: 2022-03-17
modified: 2025-07-18
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains:
- \Software\Microsoft\Windows\CurrentVersion\Run
- \Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
- \Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Details|contains:
- powershell
- "pwsh "
- FromBase64String
- .DownloadFile(
- .DownloadString(
- " -w hidden "
- " -w 1 "
- -windowstyle hidden
- -window hidden
- " -nop "
- " -encodedcommand "
- -ExecutionPolicy Bypass
- Invoke-Expression
- IEX (
- Invoke-Command
- ICM -
- Invoke-WebRequest
- "IWR "
- Invoke-RestMethod
- "IRM "
- " -noni "
- " -noninteractive "
condition: selection
falsepositives:
- Legitimate admin or third party scripts. Baseline according to your environment
level: medium
license: DRL-1.1
related:
- id: 8d85cf08-bf97-4260-ba49-986a2a65129c
type: derived