For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual process accessed the PowerShell history file

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

Command and Scripting Interpreter: PowerShell (T1059.001)

Severity

Informational

Description

An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary.

Attacker's Goals

An attacker is attempting to run PowerShell without powershell.exe to evade detection.

Investigative actions

  • Investigate the process and command line executed and whether it's benign or normal for this host.

Was this helpful?