Analytics BIOC Informational

Unusual process accessed the PowerShell history file

An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:

An attacker is attempting to run PowerShell without powershell.exe to evade detection.

Investigative actions:

Investigate the process and command line executed and whether it's benign or normal for this host.

Test period:
N/A (single event)
Deduplication:
1 Day