LoFP LoFP / t1059.001

t1059.001

TitleTags
administrative activity
administrative script libraries
administrative scripts
administrative scripts that use the same keywords.
administrator script
administrator scripts
amazon ssm document worker
appvclient
ccm
citrix configsync.ps1
depending on the scripts, this rule might require some initial tuning to fit the environment
direct ps command execution through sqlps.exe is uncommon, childprocess sqlps.exe spawned by sqlagent.exe is a legitimate action.
direct ps command execution through sqltoolsps.exe is uncommon, childprocess sqltoolsps.exe spawned by smss.exe is a legitimate action.
high
in rare administrative cases, this function might be used to check network connectivity
legitimate administrative script
legitimate certificate exports by administrators. additional filters might be required.
legitimate commands in .lnk files
legitimate powershell web access installations by administrators
legitimate scripts that use iex
legitimate usage of dsinternals for administration or audit purpose.
legitimate usage of remote powershell, e.g. for monitoring purposes.
legitimate usage of remote powershell, e.g. remote administration and monitoring.
legitimate use of pester for writing tests for powershell scripts and modules
legitimate use of remote powershell execution
legitimate use remote powershell sessions
legitimate use to pass password to different powershell commands
legitimate user creation
likely
likely. many admin scripts and tools leverage powershell in their bat or vb scripts which may trigger this rule often. it is best to add additional filters or use this to hunt for anomalies
microsoft operations manager (mom)
microsoft sccm
moderate-to-low; despite the shorter length/lower entropy for some of these, because of high specificity, fp appears to be fairly limited in many environments.
msp detection searcher
network service user name of a not-covered localization
other programs that use these command line option and accepts an 'all' parameter
other scripts
other tools that incidentally use the same command line parameters
other tools that work with encoded scripts in the command line instead of script files
powershell scripts running as system user
powershell scripts that download content from the internet
programs using powershell directly without invocation of a dedicated interpreter.
software installers that pull packages from remote systems and execute them
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
this activity may be used by legitimate software, such as patch management tools or software updaters. investigate any such activity and apply the necessary filter.
unknown
unlikely
unlikely, since this event notifies about blocked application execution. tune your applocker rules to avoid blocking legitimate applications.
use of get-command and get-help modules to reference invoke-webrequest and start-bitstransfer.
used by microsoft sql server management studio
used by some .net binaries, minimal on user workstation.
valid changes to the startup script
very special / sneaky powershell scripts
windows defender atp
winrm