Analytics BIOC Informational

Suspicious process loads a known PowerShell module

A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:

An attacker is attempting to run PowerShell without PowerShell.exe to evade detection.

Investigative actions:

Investigate the process and command line executed and whether it's benign or normal for this host.

Test period:
N/A (single event)
Deduplication:
8 Hours
2 variations:
  • Suspicious unsigned process loads a known PowerShell module Low (parent: Informational)
  • Office process loads a known PowerShell DLL High (parent: Informational)