Analytics BIOC
Informational
✕
LOLBIN created a PSScriptPolicyTest PowerShell script file
A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Executing PowerShell scripts in a stealthy manner.
Investigative actions:
Investigate the process and command line that created the file and whether it's benign or normal for this host. Investigate the created PowerShell file for potential malicious commands.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- LOLBIN created a larger than usual PSScriptPolicyTest PowerShell script file Medium (parent: Informational)