Analytics BIOC
Informational
✕
Unusual process accessed the PowerShell history file
An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:
An attacker is attempting to run PowerShell without powershell.exe to evade detection.
Investigative actions:
Investigate the process and command line executed and whether it's benign or normal for this host.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day