BIOC
Informational
✕
Windows PowerShell Logging being disabled via Registry
Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Indicator Blocking (T1562.006)
Indicator:
Registry action type = set_registry_value , delete_registry_value AND registry data = 0 , None AND registry key name = *Policies\Microsoft\Windows\PowerShell\ModuleLogging* AND registry value name = EnableModuleLogging Process initiator cmd != *gpsvc* AND *netsvcs* Host host os = windows
Preventable: yes