{"id":"T1546.013","name":"PowerShell Profile","url":"https://attack.mitre.org/techniques/T1546/013","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0451","stix_id":"x-mitre-detection-strategy--f31ad178-1f54-41a6-b286-8040e7eb7158","name":"Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification","url":"https://attack.mitre.org/detectionstrategies/DET0451","analytics":[{"id":"AN1245","stix_id":"x-mitre-analytic--298d1a46-ec12-4cd2-acce-7e0f849c384d","name":"Analytic 1245","description":"Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0451#AN1245","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"Execution of PowerShell without -NoProfile flag","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"ProfilePathList","description":"Custom PowerShell host profiles or redirection to alternate profile paths"},{"field":"ExecutionContext","description":"Whether profile execution occurs under elevated user (e.g., Administrator, SYSTEM)"},{"field":"ModuleOrScriptName","description":"Specific modules or external programs loaded within profile"},{"field":"TimeWindow","description":"Correlation time between profile modification and PowerShell process start"}],"live":true,"detection_strategies":["DET0451"],"techniques":["T1546.013"]}],"live":true,"version":"1.0","techniques":["T1546.013"]}],"sigma_rules":[{"id":"05b3e303-faf0-4f4a-9b30-46cc13e69152","title":"Potential Persistence Via PowerShell User Profile Using Add-Content","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-08-18","modified":"2023-05-04","description":"Detects calls to \"Add-Content\" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.013/T1546.013.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.013"],"path":"rules/windows/powershell/powershell_script/posh_ps_user_profile_tampering.yml","techniques":["T1546.013"],"cves":[]},{"id":"3a9fa2ec-30bc-4ebd-b49e-7c9cff225502","title":"VsCode Powershell Profile Modification","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-24","modified":"2023-01-06","description":"Detects the creation or modification of a vscode related powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence","references":["https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_profiles?view=powershell-7.2"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.013"],"path":"rules/windows/file/file_event/file_event_win_susp_vscode_powershell_profile.yml","techniques":["T1546.013"],"cves":[]},{"id":"b5b78988-486d-4a80-b991-930eff3ff8bf","title":"PowerShell Profile Modification","author":"HieuTT35, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2019-10-24","modified":"2023-10-23","description":"Detects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence","references":["https://www.welivesecurity.com/2019/05/29/turla-powershell-usage/","https://persistence-info.github.io/Data/powershellprofile.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.013"],"path":"rules/windows/file/file_event/file_event_win_susp_powershell_profile.yml","techniques":["T1546.013"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}