Analytics BIOC
Medium
✕
PowerShell suspicious flags
Abbreviated flags in PowerShell indicate malicious intent.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Run code to perform actions or download other malicious programs.
Investigative actions:
Check if the initiator process is malicious. Check for other operations by the PowerShell instance.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days