PowerShell suspicious flags
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: PowerShell (T1059.001)
Severity
Medium
Description
Abbreviated flags in PowerShell indicate malicious intent.
Attacker's Goals
Run code to perform actions or download other malicious programs.
Investigative actions
Check if the initiator process is malicious.
Check for other operations by the PowerShell instance.
PreviousPowerShell runs suspicious base64-encoded commands
NextPowerShell used to export mailbox contents
Was this helpful?
