Malicious Powershell Process - Encoded Command

Description

This search looks for PowerShell processes that have encoded the script within the command-line. Malware has been seen using this parameter, as it obfuscates the code and makes it relatively easy to pass a script on the command-line.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Advanced Threat Detection

Category

Endpoint Compromise

Alert Volume

This search looks for PowerShell processes that have encoded the script within the command-line. Malware has been seen using this parameter, as it obfuscates the code and makes it relatively easy to pass a script on the command-line.

SPL Difficulty

None

Journey

Stage 3

MITRE ATT&CK Tactics

Defense Evasion

MITRE ATT&CK Techniques

Obfuscated Files or Information

Obfuscated Files or Information

MITRE Threat Groups

APT-C-36
APT18
APT19
APT28
APT29
APT3
APT32
APT33
APT37
APT41
BlackOasis
Blue Mockingbird
Chimera
Cobalt Group
Dark Caracal
Darkhotel
Dust Storm
Elderwood
FIN6
FIN7
FIN8
Frankenstein
Gallmaker
Gamaredon Group
Group5
Honeybee
Inception
Lazarus Group
Leafminer
Leviathan
Machete
Magic Hound
Mofang
Molerats
MuddyWater
Night Dragon
OilRig
Patchwork
Putter Panda
Rocke
Sandworm Team
Silence
Soft Cell
TA505
Threat Group-3390
Tropic Trooper
Turla
Whitefly
Wizard Spider
menuPass

Kill Chain Phases

Command and Control
Actions On Objectives

   Help

Malicious Powershell Process - Encoded Command Help

You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model.

   Search

Open in Search