← Back to Explore
T1546.013
PowerShell Profile
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (<code>profile.ps1</code>) is a script that runs when [PowerShell](https://attack.mitre.org/techniques/T1059/001) starts and can be used as a logon script to customize user environments. [PowerShell](https://attack.mitre.org/techniques/T1059/001) supports several profiles depending on the user or host program. For example, there can be different profiles...
Windows
4
Detections
2
Sources
1
Threat Actors
BY SOURCE
3sigma1elastic
PROCEDURES (3)
Powershell2 detections
Auto-extracted: 2 detections for powershell
Powershell1 detections
Auto-extracted: 1 detections for powershell
Suspicious1 detections
Auto-extracted: 1 detections for suspicious