BIOC Informational

Windows PowerShell Logging being disabled via Registry

Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Indicator Blocking (T1562.006)
Indicator:

Registry action type = set_registry_value , delete_registry_value AND registry data = 0 , None AND registry key name = *Policies\Microsoft\Windows\PowerShell\ModuleLogging* AND registry value name = EnableModuleLogging Process initiator cmd != *gpsvc* AND *netsvcs* Host host os = windows

Preventable: yes