Azure VM Run Command operations executing a unique PowerShell script

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when Azure Run command is used to execute a PowerShell script on a VM that is unique. The uniqueness of the PowerShell script is determined by taking a combined hash of the cmdLets it imports and the file size of the PowerShell script. Alerts from this detection indicate a unique PowerShell was executed in your environment.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 5239248b-abfb-4c6a-8177-b104ade5db56
Severity Medium
Kind Scheduled
Tactics LateralMovement, Execution
Techniques T1570, T1059.001
Required Connectors AzureActivity, MicrosoftThreatProtection
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules