Suspicious PowerShell Enumeration of Running Processes
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Process Discovery (T1057)
Severity
Informational
Description
Attackers often enumerate running processes to find and disable security tools.
Attacker's Goals
Understand the type of host according to the processes running on it; find and disable security tools.
Investigative actions
Verify whether the command that was executed is benign or normal for the host and/or user performing it (for example, it may be an IT script).
PreviousSuspicious PowerShell Command Line
NextSuspicious PowerSploit's recon module (PowerView) net function was executed
Was this helpful?
