ClickFix - PowerShell executed through the run application
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Execution (TA0002), Initial Access (TA0001)
ATT&CK Technique
User Execution (T1204), Phishing (T1566)
Severity
Low
Description
An attacker may be trying to trick a user to execute PowerShell through the run application.
Attacker's Goals
An attacker may be trying to trick a user to execute PowerShell through the run application.
Investigative actions
Check if the command line is known in the organization or malicious.
And ask the user what is the source of it.
Variations
PreviousChrome OS Remote Access policy was modified in Google Workspace
NextCloud access key creation
Was this helpful?
