# Problem with PowerShell security rules that use process.args

**URL:** <https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861>\
**Category:** Elastic Security\
**Created:** [March 2, 2023, 2:17pm UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861 "2023-03-02T14:17:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maretti/32/118976_2.png) [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Post date:** [March 2, 2023, 2:17pm UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861/1 "2023-03-02T14:17:44Z")

</div>

# The Problem

Rules that are based off powershell like `Disabling Windows Defender Security Settings via PowerShell` and `Windows Firewall Disabled via PowerShell` are not giving alerts back.

[Windows Firewall Disabled via PowerShell | Elastic Security Solution [8.6] | Elastic](https://www.elastic.co/guide/en/security/current/windows-firewall-disabled-via-powershell.html)

[Disabling Windows Defender Security Settings via PowerShell | Elastic Security Solution [8.6] | Elastic](https://www.elastic.co/guide/en/security/current/disabling-windows-defender-security-settings-via-powershell.html)

These are the query's those rules filter on they use the process.args field to filter on commands

```python
process where event.type == "start" and (process.name :
("powershell.exe", "pwsh.exe", "powershell_ise.exe") or
process.pe.original_file_name in ("powershell.exe", "pwsh.dll",
"powershell_ise.exe")) and process.args : "Set-MpPreference" and
process.args : ("-Disable*", "Disabled", "NeverSend", "-Exclusion*")

```

```python
process where event.action == "start" and (process.name :
("powershell.exe", "pwsh.exe", "powershell_ise.exe") or
process.pe.original_file_name == "PowerShell.EXE") and process.args
: "*Set-NetFirewallProfile*" and (process.args : "*-Enabled*" and
process.args : "*False*") and (process.args : "*-All*" or
process.args : ("*Public*", "*Domain*", "*Private*"))

```

Most of the `powershell.exe` args are empty and the rules check on the args.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/4/54d0c84b482ee091ff33ddd533bcf4dcc345458d.png)

The operational logs of powershell seem to have the data I need

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27270c733282f0da5933e433c38a1a8ddc7c6b88.png)

To grab this data into elastic I will need a custom windows log integration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/7/0773059d3fcf6a09c24f4bb831aff5d200c56d92.png)

Does not use the process.args field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d1fa6f6dfb654fd8091a1231037237683961d5ae.png)

Anyone that has an idea what I am doing wrong here?

I could edit the rule to filter on winlog.event\_data.ScriptBlockText but I would like to know why the process.args field isn't working

---

<div class="post-metadata">

**Author:** ![Sebastian\_Huettersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_huettersen/32/117296_2.png) [@Sebastian\_Huettersen](https://discuss.elastic.co/u/Sebastian_Huettersen)\
**Post date:** [March 2, 2023, 6:26pm UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861/2 "2023-03-02T18:26:15Z")

</div>

Hey @Maretti ,

is there a reason why you don't use the [windows](https://docs.elastic.co/integrations/windows) or [defend](https://docs.elastic.co/integrations/endpoint) integration?  
If you want to use the Custom Windows event integration you need to set up a pipeline under advanced options to normalize your data. Have a look at the windows [integration](https://github.com/elastic/integrations/blob/main/packages/windows/data_stream/powershell/elasticsearch/ingest_pipeline/default.yml).

Regards,

Sebastian

---

<div class="post-metadata">

**Author:** ![Maretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maretti/32/118976_2.png) [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Post date:** [March 6, 2023, 9:58am UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861/3 "2023-03-06T09:58:32Z")

</div>

Hi,

I did use the windows and defend integration. I tested it the wrong way

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb03f508e2ff395e098238bba39ece033cc3efdb.png)

In the first log entry we do get the arguments and the process is ran like this:

```plaintext
powershell.exe Set-NetFirewallProfile -Enabled True

```

In the second one we do not get the arguments and the process is ran like this:

```plaintext
Set-NetFirewallProfile -Enabled False

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2023, 9:58am UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861/4 "2023-04-03T09:58:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
