Azure VM Run Command operations executing a unique PowerShell script

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies when Azure Run command is used to execute a PowerShell script on a VM that is unique. The uniqueness of the PowerShell script is determined by taking a combined hash of the cmdLets it imports and the file size of the PowerShell script. Alerts from this detection indicate a unique PowerShell was executed in your environment.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 5239248b-abfb-4c6a-8177-b104ade5db56
Severity Medium
Kind Scheduled
Tactics LateralMovement, Execution
Techniques T1570, T1059.001
Required Connectors AzureActivity, MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AzureActivity ? ?
DeviceEvents ?
DeviceFileEvents ?

Associated Connectors

The following connectors provide data for this content item:

Connector Solution
AzureActivity Azure Activity

Solutions: Azure Activity


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules