powershell_ise.exe
- File Path:
C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell_ise.exe
- Description: Windows PowerShell ISE
Screenshot
Hashes
Type | Hash |
---|---|
MD5 | 2A02490E8930ACC10F135F86F7A4BAE9 |
SHA1 | ECB451B63117E8A38932EBBFEEC03873C21D4E31 |
SHA256 | DF54CBE8AD814AE09766F3CDB5C3BCA9BD407621211DAA23194E58533837D2E0 |
SHA384 | AD7F1C23DA1C30B8CA529BFBFF588A7897251F749D08DC768684E0A304843CFCBDACD4CD3DA9227950EA2E969D6938EA |
SHA512 | 5AAB32112195A6CE0F93378B622A7A3C64AB8D7751774C767B6144EF2090B1FFFE1DA592E4E373907767DCE46C9496F6CCB922C8D3978E7703ED953A109D2DB1 |
SSDEEP | 3072:99kVjGPsw40pLkVjqP4w6U+ToIuWNXmmZTWl/jC7gDooMLGW:DkKuZToIuUXmmZbgDooMD |
PESHA1 | 3717581FF291A6E8F68F975C5D9E2737752EAD42 |
PE256 | D1718C090B594CC98D27A94C13D95B19A5BDCFA09A733661C70C3A519EDB4655 |
Runtime Data
Window Title:
Windows PowerShell ISE
Open Handles:
Path | Type |
---|---|
(R-D) C:\Windows\Fonts\StaticCache.dat | File |
(R-D) C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | File |
(R-D) C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll | File |
(R-D) C:\Windows\System32\en-US\winnlsres.dll.mui | File |
(R-D) C:\Windows\SystemResources\imageres.dll.mun | File |
(RW-) C:\Windows\System32 | File |
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22000.120_none_9d947278b86cc467 | File |
...\Cor_SxSPublic_IPCBlock | Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db | Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db | Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro | Section |
\BaseNamedObjects\Cor_Private_IPCBlock_v4_5232 | Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 | Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 | Section |
\Sessions\2\Windows\Theme1077709572 | Section |
\Windows\Theme3461253685 | Section |
Loaded Modules:
Path |
---|
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
C:\WINDOWS\System32\ADVAPI32.dll |
C:\WINDOWS\System32\KERNEL32.dll |
C:\WINDOWS\System32\KERNELBASE.dll |
C:\WINDOWS\SYSTEM32\MSCOREE.DLL |
C:\WINDOWS\System32\msvcrt.dll |
C:\WINDOWS\SYSTEM32\ntdll.dll |
C:\WINDOWS\System32\RPCRT4.dll |
C:\WINDOWS\System32\sechost.dll |
C:\WINDOWS\System32\SHLWAPI.dll |
C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell_ise.exe |
Signature
- Status: Signature verified.
- Serial:
33000002ED2C45E4C145CF48440000000002ED
- Thumbprint:
312860D2047EB81F8F58C29FF19ECDB4C634CF6A
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: powershell_ise.EXE
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.22000.1 (WinBuild.160101.0800)
- Product Version: 10.0.22000.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/73
- VirusTotal Link: https://www.virustotal.com/gui/file/df54cbe8ad814ae09766f3cdb5c3bca9bd407621211daa23194e58533837d2e0/detection
File Similarity (ssdeep match)
Possible Misuse
The following table contains possible examples of powershell_ise.exe
being misused. While powershell_ise.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | image_load_in_memory_powershell.yml | - '\powershell_ise.exe' |
DRL 1.0 |
sigma | pipe_created_alternate_powershell_hosts_pipe.yml | - '\powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_renamed_binary.yml | - 'powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_renamed_binary.yml | - '\powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_renamed_binary_highly_relevant.yml | - 'powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_renamed_binary_highly_relevant.yml | - '\powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_renamed_powershell.yml | - '\powershell_ise.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_bitstransfer.yml | - '\powershell_ise.exe' |
DRL 1.0 |
atomic-red-team | T1059.001.md | 1. Open Powershell_ise as a Privileged Account | MIT License. © 2018 Red Canary |
Additional Info*
*The information below is copied from MicrosoftDocs, which is maintained by Microsoft. Available under CC BY 4.0 license.
PowerShell_ise
Windows PowerShell Integrated Scripting Environment (ISE) is a graphical host application that enables you to read, write, run, debug, and test scripts and modules in a graphic-assisted environment. Key features such as IntelliSense, Show-Command, snippets, tab completion, syntax-coloring, visual debugging, and context-sensitive Help provide a rich scripting experience.
Using PowerShell.exe
The PowerShell_ISE.exe tool starts a Windows PowerShell ISE session. When you use PowerShell_ISE.exe, you can use its optional parameters to open files in Windows PowerShell ISE or to start a Windows PowerShell ISE session with no profile or with a multithreaded apartment.
-
To start a Windows PowerShell ISE session in a Command Prompt window, in Windows PowerShell, or at the Start menu, type:
PowerShell_Ise.exe
-
To open a script (.ps1), script module (.psm1), module manifest (.psd1), XML file, or any other supported file in Windows PowerShell ISE, type:
PowerShell_Ise.exe <filepath>
In Windows PowerShell 3.0, you can use the optional File parameter as follows:
PowerShell_Ise.exe -file <filepath>
-
To start a Windows PowerShell ISE session without your Windows PowerShell profiles, use the NoProfile parameter. (The NoProfile parameter is introduced in Windows PowerShell 3.0.), type:
PowerShell_Ise.exe -NoProfile
-
To see the PowerShell_ISE.exe help file, type:
PowerShell_Ise.exe -help PowerShell_Ise.exe -? PowerShell_Ise.exe /?
Remarks
-
For a complete list of the PowerShell_ISE.exe command-line parameters, see about_PowerShell_Ise.Exe.
-
For information about other ways to start Windows PowerShell, see Starting Windows PowerShell.
-
Windows PowerShell runs on the Server Core installation option of Windows Server operating systems. However, because Windows PowerShell ISE requires a graphic user interface, it does not run on Server Core installations.
Additional References
MIT License. Copyright (c) 2020-2021 Strontic.