{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/elastic-agent-system-windows-integration/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kibana 9.4.0+","Elastic Agent System Windows Integration"],"_cs_severities":["low"],"_cs_tags":["windows","machine-learning","powershell","execution","threat-detection"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eElastic has developed a machine learning rule to identify the execution of rare PowerShell scripts on Windows systems, leveraging script block hashes to detect deviations from established environmental baselines. This detection method focuses on scripts that have rarely or never been observed within a specific Windows host's historical activity, differentiating it from entropy-based anomaly detection. The objective is to uncover potentially malicious activity such as malware execution, the establishment of persistence mechanisms, or other suspicious behaviors that leverage PowerShell. This rule is integrated into the Elastic security platform, requiring specific ML jobs and data from the Windows integration to be active in Kibana version 9.4.0 or higher. While the rule identifies unusual behavior, false positives may occur with newly installed legitimate programs or infrequently run legitimate scripts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003eThis brief describes a detection methodology rather than a specific attack chain. The Elastic machine learning rule is designed to identify the \u003cem\u003eexecution\u003c/em\u003e phase of an attack, specifically focusing on the rarity of PowerShell script blocks. When an attacker executes a novel or infrequently used PowerShell script, whether for initial payload delivery, command and control, persistence, or data exfiltration, this ML rule aims to flag the anomalous execution. It does not cover the initial access vector but rather the post-exploitation activity where PowerShell is often heavily utilized. The detection focuses on the inherent unusualness of the script itself within the context of the monitored environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful execution of rare PowerShell scripts, if malicious, can lead to severe consequences, including system compromise, data theft, and the deployment of ransomware. Such scripts are frequently used by threat actors for various post-exploitation activities like privilege escalation, lateral movement, establishing persistence, or directly executing payloads. If this activity goes undetected, attackers can maintain a foothold within the network, escalate privileges, exfiltrate sensitive data, disrupt operations through ransomware, or deploy destructive malware. Early detection of such anomalous PowerShell usage is critical for containing potential breaches and mitigating their impact before significant damage occurs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the \u003ccode\u003ev3_windows_rare_script_ea\u003c/code\u003e machine learning job to your Elastic environment to enable this detection rule.\u003c/li\u003e\n\u003cli\u003eEnsure the Elastic Agent System \u003ccode\u003ewindows\u003c/code\u003e integration is properly configured and collecting PowerShell script block logs on all Windows hosts.\u003c/li\u003e\n\u003cli\u003eUpon detection, investigate the PowerShell script block hash by retrieving the full script content and examining it for malicious indicators using tools like VirusTotal, Hybrid-Analysis, or Any.run.\u003c/li\u003e\n\u003cli\u003eAnalyze the process execution chain (parent process tree) of the PowerShell process flagged by the rule to determine its origin and legitimacy.\u003c/li\u003e\n\u003cli\u003eReview the \u003ccode\u003euser.name\u003c/code\u003e field associated with the alert to determine if the activity is part of an expected workflow for that user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T15:31:41Z","date_published":"2026-07-27T15:31:41Z","id":"https://feed.craftedsignal.io/briefs/2026-07-rare-powershell-script/","summary":"Elastic's machine learning job detects rare PowerShell script executions on Windows hosts, identified by their script block hash, indicating potential malware activity or persistence mechanisms that deviate from an established baseline.","title":"Detection of Rare PowerShell Scripts on Windows Systems","url":"https://feed.craftedsignal.io/briefs/2026-07-rare-powershell-script/"}],"language":"en","title":"CraftedSignal Threat Feed - Elastic Agent System Windows Integration","version":"https://jsonfeed.org/version/1.1"}