Powershell Creating Thread Mutex

Powershell Creating Thread Mutex


The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using the mutex function. This function is commonly seen in some obfuscated PowerShell scripts to make sure that only one instance of there process is running on a compromise machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.


Powershell Creating Thread Mutex Help

To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/


Open in Search