For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious PowerShell Enumeration of Running Processes

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Process Discovery (T1057)

Severity

Informational

Description

Attackers often enumerate running processes to find and disable security tools.

Attacker's Goals

Understand the type of host according to the processes running on it; find and disable security tools.

Investigative actions

Verify whether the command that was executed is benign or normal for the host and/or user performing it (for example, it may be an IT script).

Was this helpful?