# PowerShell Keylogging Script potential False Positive

**URL:** <https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364>\
**Category:** Elastic Security\
**Created:** [March 10, 2022, 7:41pm UTC](https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364 "2022-03-10T19:41:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gicetek](https://avatars.discourse-cdn.com/v4/letter/g/bcef8e/32.png) [@gicetek](https://discuss.elastic.co/u/gicetek)\
**Post date:** [March 10, 2022, 7:41pm UTC](https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364/1 "2022-03-10T19:41:05Z")

</div>

I recently enabled a number of the provided rules in our test Elasticsearch/Kibana/Winlogbeat configuration and am seeing alerts on the "PowerShell Keylogging Script" rule every time I run nearly any powershell command on any of the Windows boxes I manage. That rule has the following detection:

event.category:process and  
(  
powershell.file.script\_block\_text : (GetAsyncKeyState or NtUserGetAsyncKeyState or GetKeyboardState or Get-Keystrokes) or  
powershell.file.script\_block\_text : ((SetWindowsHookA or SetWindowsHookW or SetWindowsHookEx or SetWindowsHookExA or NtUserSetWindowsHookEx) and (GetForegroundWindow or GetWindowTextA or GetWindowTextW or WM\_KEYBOARD\_LL))  
)

Through process of elimination, I was able to narrow down the string triggering the rule to "Get-Keystrokes". i.e if I create a custom rule that's a copy of the one above, and remove "Get-Keystrokes", the rule stops triggering. I can search in the discover interface and see that indeed I have results from that search.

My confusion is that none of the text in the message or script\_block\_text contains that string and none of the Powershell I'm running does either. When I search in discover for the string, I can't find the string in any of the result json either.

Here's an example of powershell that triggers it:

`Get-PSRepository | Where-Object { $_.Name -eq "PSGallery" -and $_.InstallationPolicy -ne "Trusted" }`

My question is essentially, what is causing the rule to fire and how can I verify the alert is a false positive, or not.

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [April 7, 2022, 3:33am UTC](https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364/2 "2022-04-07T03:33:21Z")

</div>

I am facing the same issue - that the mentioned rule (`PowerShell Keylogging Script`) triggers many false positives.

I suspect that the `-` in `Get-Keystrokes` means that any `-` in the `powershell.file.script_block_text` field's value would result in the rule being triggered.

This issue of having many false positives is similarly seen in the `PowerShell Suspicious Script with Audio Capture Capabilities` rule.

Its query is: `event.category:process and powershell.file.script_block_text:(Get-MicrophoneAudio)`. This rule is clearer in showing that the `-` (in my opinion) character is the one that is triggering the rule detection, since there is only 1 value in `powershell.file.script_block_text` here.

May I ask how we are able to debug this?

Thank you.

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [April 18, 2022, 3:36am UTC](https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364/3 "2022-04-18T03:36:07Z")

</div>

Bump!

Still looking for ways to debug this issue - to find out if our concerns are legitimate.

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2022, 3:37am UTC](https://discuss.elastic.co/t/powershell-keylogging-script-potential-false-positive/299364/4 "2022-05-16T03:37:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
