LOLBIN created a PSScriptPolicyTest PowerShell script file
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: PowerShell (T1059.001)
Severity
Informational
Description
A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.
Attacker's Goals
Executing PowerShell scripts in a stealthy manner.
Investigative actions
Investigate the process and command line that created the file and whether it's benign or normal for this host.
Investigate the created PowerShell file for potential malicious commands.
Variations
PreviousLOLBAS executable injects into another process
NextLOLBIN process executed with a high integrity level
Was this helpful?
