Analytics BIOC Informational

LOLBIN created a PSScriptPolicyTest PowerShell script file

A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Executing PowerShell scripts in a stealthy manner.

Investigative actions:

Investigate the process and command line that created the file and whether it's benign or normal for this host. Investigate the created PowerShell file for potential malicious commands.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • LOLBIN created a larger than usual PSScriptPolicyTest PowerShell script file Medium (parent: Informational)