PowerShell Encoded Command Execution

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Looks for variations of the PowerShell -EncodedCommand parameter, commonly used to obfuscate commands. Not all occurrences are malicious, so base64 decode the command for analysis. Tune noisy results by grouping on parent process or rare commands.

Attribute Value
Type Hunting Query
Solution Intel471
ID 3a5a21fd-5a82-45dc-ad37-3fb95f475e11
Tactics DefenseEvasion, Execution
Techniques T1027, T1059.001
Required Connectors SecurityEvents, WindowsSecurityEvents, MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceEvents ✓ ✗ ✓
SecurityEvent ParentProcessName endswith "gc_worker.exe"
ParentProcessName has "Plugins\\Microsoft.GuestConfiguration.ConfigurationforWindows"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471