Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Looks for variations of the PowerShell -EncodedCommand parameter, commonly used to obfuscate commands. Not all occurrences are malicious, so base64 decode the command for analysis. Tune noisy results by grouping on parent process or rare commands.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 3a5a21fd-5a82-45dc-ad37-3fb95f475e11 |
| Tactics | DefenseEvasion, Execution |
| Techniques | T1027, T1059.001 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents, MicrosoftThreatProtection |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
DeviceEvents |
✓ | ✗ | ✓ | |
SecurityEvent |
ParentProcessName endswith "gc_worker.exe"ParentProcessName has "Plugins\\Microsoft.GuestConfiguration.ConfigurationforWindows" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊