Analytics BIOC
Informational
✕
Suspicious process loads a known PowerShell module
A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:
An attacker is attempting to run PowerShell without PowerShell.exe to evade detection.
Investigative actions:
Investigate the process and command line executed and whether it's benign or normal for this host.
- Test period:
- N/A (single event)
- Deduplication:
- 8 Hours
2 variations:
- Suspicious unsigned process loads a known PowerShell module Low (parent: Informational)
- Office process loads a known PowerShell DLL High (parent: Informational)