Elastic low stable eql

Rare Powershell Script

A machine learning job detected a rare PowerShell script, identified by its script block hash, that may indicate execution of malware, or persistence mechanisms. Unlike anomaly detection based on content entropy, this rule identifies scripts that have rarely or never been seen in the environment.

View Source

Detection Logic

False Positives

  • A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this alert. PowerShell scripts that are new to the environment or run infrequently may trigger this alert.

Field Validations

Loading…

Comments (0)

Loading comments...