Elastic low stable eql
Rare Powershell Script
A machine learning job detected a rare PowerShell script, identified by its script block hash, that may indicate execution of malware, or persistence mechanisms. Unlike anomaly detection based on content entropy, this rule identifies scripts that have rarely or never been seen in the environment.
Detection Logic
False Positives
- ⚠ A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this alert. PowerShell scripts that are new to the environment or run infrequently may trigger this alert.
Field Validations
Loading…
Comments (0)
Loading comments...