Elastic low stable eql

Suspicious Powershell Script

A machine learning job detected a PowerShell script with unusual data characteristics, such as obfuscation, that may be a characteristic of malicious PowerShell script text blocks.

View Source

Detection Logic

False Positives

  • Certain kinds of security testing may trigger this alert. PowerShell scripts that use high levels of obfuscation or have unusual script block payloads may trigger this alert.

Field Validations

Loading…

Comments (0)

Loading comments...