Compliance Node Overview
MITRE ATT&CK T1546.013 (PowerShell Profile) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (profile.ps1) is a script that runs when PowerShell starts and can be used as a logon script to customize user environments. PowerShell supports several profiles depending on the user or host program. For example, there can be different profiles for PowerShell host programs such as the PowerShell console, PowerShell ISE or Visual Studio Code. Affected platforms: Windows. MITRE-documented mitigations include M1045 Code Signing, M1022 Restrict File and Directory Permissions, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-03, CM-06, CM-10.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/013/
SHA-256 integrity: 31d0af0343121a811acae2d4c004b73bd60d72cfaee1daff320e43e76b162422
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1546.013: PowerShell Profile (https://attack.mitre.org/techniques/T1546/013/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access