Techniques
Sample rules
Suspicious Powershell Script
- source: elastic
- technicques:
- T1059
Description
A machine learning job detected a PowerShell script with unusual data characteristics, such as obfuscation, that may be a characteristic of malicious PowerShell script text blocks.
Detection logic