Analytics BIOC
Low
✕
ClickFix - PowerShell executed through the run application
An attacker may be trying to trick a user to execute PowerShell through the run application.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Initial Access (TA0001)
ATT&CK techniques: User Execution (T1204) Phishing (T1566)
Attacker's goals:
An attacker may be trying to trick a user to execute PowerShell through the run application.
Investigative actions:
Check if the command line is known in the organization or malicious. And ask the user what is the source of it.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- ClickFix - PowerShell command executed through the run application and using Invoke-Expression cmdlet High (parent: Low)
- ClickFix - Long PowerShell command executed through the run application with URL in the command High (parent: Low)
- ClickFix - Long encoded PowerShell command executed through the run application High (parent: Low)
- ClickFix - Schedule task PowerShell command executed through the run application High (parent: Low)