Log sources › WinEventLog:PowerShell
WinEventLog:PowerShell
Inverted view: what can be detected if this is the log you have. Office Suite, Windows
13
channels
65
analytics
64
techniques
26
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
CmdletName: Get-Recipient, Get-User |
DC0064 Command Execution | AN1089 | 1 |
CommandLine=copy-item or robocopy from UNC path |
DC0064 Command Execution | AN0194 | 1 |
EventCode=400, 403 |
DC0034 Process Metadata | AN1252 | 1 |
EventCode=4103, 4104, 4105, 4106 |
DC0029 Script Execution DC0064 Command Execution |
AN0037 AN0089 AN0131 AN0152 AN0182 AN0254 AN0271 AN0274 AN0286 AN0345 AN0363 AN0388 AN0392 AN0430 AN0455 AN0469 AN0472 AN0507 AN0513 AN0551 AN0559 AN0589 AN0622 AN0641 AN0737 AN0834 AN0903 AN0927 AN0932 AN0962 AN1015 AN1025 AN1028 AN1177 AN1207 AN1220 AN1252 AN1280 AN1288 AN1305 AN1309 AN1325 AN1440 AN1448 AN1452 AN1461 AN1464 AN1551 AN1557 AN1567 AN1589 AN1621 AN2030 AN2063 | 54 |
Exchange Cmdlets |
DC0064 Command Execution | AN0740 | 1 |
Execution of 'Get-WmiObject Win32_Product' or similar PowerShell cmdlets |
DC0064 Command Execution | AN1100 | 1 |
Execution of Microsoft script to enumerate custom forms in Outlook mailbox |
DC0064 Command Execution | AN0085 | 1 |
Execution of PowerShell script to enumerate or remove malicious Home Page folder config |
DC0064 Command Execution | AN0502 | 1 |
Execution of PowerShell without -NoProfile flag |
DC0064 Command Execution | AN1245 | 1 |
Get-ADTrust|GetAllTrustRelationships |
DC0064 Command Execution | AN0016 | 1 |
PowerShell launched from outlook.exe or triggered without user invocation |
DC0064 Command Execution | AN0263 | 1 |
Scripts with references to XML parsing, AES decryption, or gpprefdecrypt logic |
DC0029 Script Execution | AN1075 | 1 |
Set-ADUser or Set-ADAuthenticationPolicy with MFA attributes disabled |
DC0029 Script Execution | AN0543 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2012-0767 | Adobe Flash Player | T1114.002 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1007 T1082 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1114 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1087.002 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1217 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1070.004 | Stale |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1016 T1082 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1070.004 T1087.002 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1070.004 T1087.002 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1069 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1059.001 T1482 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1049 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1033 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1070.004 T1482 | Stale |
| CVE-2023-32315 | Ignite Realtime Openfire | T1087.002 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1082 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1087.002 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1082 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1082 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1114 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1033 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1070.004 | Mapped |