T1059.001 · PowerShell
PowerShell: observe the complete process
Compare a broad rule with a parent-process condition against synthetic process-creation events.
Synthetic comparison · not run
Telemetry, references and limitations
The evidence shows how a PowerShell signal can mix legitimate administration with activity labelled malicious and how a pwsh.exe variant is missed when only powershell.exe is searched.
Synthetic process-creation events from the powershell dataset with a Sysmon logsource.
Collection prerequisites: Enable and retain Sysmon Process Create events with Image and ParentImage; retain CommandLine and User when available, without transforming paths.
Image· rule condition- Literal executable path; it is the shared condition in the preset and improved rules.
ParentImage· rule condition- Literal parent-process path; the improved variant needs it to narrow launches from WINWORD.EXE.
CommandLine· context- Command line retained as event context; it is absent from PS-07 and is not treated as a label.
User· context- Synthetic event user for administrative and activity context; it does not prove intent.
The dataset is a synthetic, simplified sample, not production telemetry. PS-07 lacks CommandLine and PS-08 is DNS; the rule performs no temporal correlation, executes no commands, and does not by itself prove an intrusion.
Legitimate activity to consider
- Authorized inventory launched by an administrator from Explorer.
- Approved maintenance with an encoded command from taskeng.exe.
- Activity from another source, such as a DNS query, outside process creation.
What this does not demonstrate
- Events, labels, and paths are synthetic and support condition comparison rather than an estimate of real protection.
- Searching only for powershell.exe misses the pwsh.exe variant; adding a parent process reduces noise in this dataset but does not cover every variant.
- Missing CommandLine context does not make an event a true negative; if a condition field is absent, the matcher does not match and the result remains limited by the labels.
Synthetic example traceability
Documentation references; not logs from a real environment: