Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapClickFix - PowerShell executed through the run application Low 4 variations
An attacker may be trying to trick a user to execute PowerShell through the run application.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Initial Access (TA0001)ATT&CK techniques: User Execution (T1204) Phishing (T1566)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An attacker may be trying to trick a user to execute PowerShell through the run application.Investigative actions: Check if the command line is known in the organization or malicious. And ask the user what is the source of it.Variations
ClickFix - PowerShell command executed through the run application and using Invoke-Expression cmdlet
High overridden
An attacker may be trying to trick a user to execute PowerShell through the run application. overridden
ClickFix - Long PowerShell command executed through the run application with URL in the command
High overridden
An attacker may be trying to trick a user to execute PowerShell through the run application. overridden
ClickFix - Long encoded PowerShell command executed through the run application
High overridden
An attacker may be trying to trick a user to execute PowerShell through the run application. overridden
ClickFix - Schedule task PowerShell command executed through the run application
High overridden
An attacker may be trying to trick a user to execute PowerShell through the run application. overridden