Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kiikoo15
Participant

Detect/Precent powershell execution

Hello everyone,

I would like to ask what is the best approach to prevent and/or monitor the execution of PowerShell scripts or even the use of the PowerShell application on the computers in my IT environment, using Check Point Endpoint Security.

My objectives are:

  • Preventing PowerShell execution (in cases where it's not required by end users);

  • Detecting/alerting when PowerShell is executed — especially in suspicious contexts (e.g., powershell.exe -Encoded Command, etc.);

  • Monitoring or blocking the creation/execution of Scheduled Tasks (schtasks.exe), which are often used for malicious persistence.

Specific questions:

  • Is it possible to create block rules to prevent PowerShell usage, while allowing exceptions if needed?

  • Are there ways to generate alerts or detailed logs when PowerShell is executed (even if it's legitimate)?

  • Does Harmony Endpoint allow for visibility over suspicious scheduled task creation?

  • Are there any best practices or recommended profiles to mitigate this type of behavior?

I appreciate any guidance or sharing of experiences with these configurations.

Best regards,
K

0 Kudos
1 Reply
lluner
Advisor

@kiikoo15 

I believe that first you could use this functionality below:

Configuring Application Permissions in the Application Control Policy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 05 Mar 2026 @ 12:00 PM (SGT)

    2026 Threat Landscape Briefing - APAC

    Thu 05 Mar 2026 @ 03:00 PM (CET)

    2026 Threat Landscape Briefing - EMEA

    Thu 05 Mar 2026 @ 11:00 AM (EST)

    Tips and Tricks 2026 #1: MCP Servers

    Thu 05 Mar 2026 @ 02:00 PM (EST)

    2026 Threat Landscape Briefing -AMER
    CheckMates Events