PSScriptPolicyTest Creation By Uncommon Process

Rule Info

Name
PSScriptPolicyTest Creation By Uncommon Process
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.
Date
2023-06-01 00:00:00
Modified
2025-10-07 00:00:00
Id
1027d292-dd87-4a1a-8701-2abe04d7783c
Tags
attack.stealth
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #5966 from @nasbench - Update mitre tags to use attack v19
2026-04-29
phantinuss
Merge PR #5679 from @swachchhanda000 - chore: update evtx baseline to v0.8.2
2025-10-09
github-actions[bot]
Merge PR #5065 from @nasbench - Promote older rules status from `experimental` to `test`
2024-11-01
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Merge PR #4577 from @nasbench - Multiple Fixes & Updates
2023-12-21
Nasreddine Bencherchali
Merge PR #4491 from @nasbench - Rule Updates & Fixes
2023-10-23
Nasreddine Bencherchali
chore: fix fp found in testing
2023-06-01