PowerShell Encoded Command Execution (Living off the Land)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects PowerShell or pwsh.exe launched with encoded command flags (-EncodedCommand, -enc, -ec, -enco). Attackers encode commands in Base64 to obfuscate malicious payloads and bypass script-based controls. Risk is elevated when a download cradle pattern is also detected. Tune AllowlistedParents for known-safe management tools such as SCCM.

Attribute Value
Type Analytic Rule
Solution Attacker Tools Threat Protection Essentials
ID 7b2f4d1a-9c3e-4f72-8b1d-3e6a9f2c4b8d
Severity Medium
Status Available
Kind Scheduled
Tactics Execution, DefenseEvasion
Techniques T1059.001, T1027
Required Connectors MicrosoftThreatProtection, SecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents ✓ ✗ ✓
SecurityEvent EventID == "4688" ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Attacker Tools Threat Protection Essentials