Analytics BIOC
Low
✕
PowerShell Initiates a Network Connection to GitHub
PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Url Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:
Download a second stage payload for execution.
Investigative actions:
Check if the initiator process is malicious. Check for additional file/network operations by the same PowerShell instance.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- PowerShell Initiates a Network Connection to GitHub from a sensitive server Medium (parent: Low)