The EncodedCommand Was Buried In Noise
The endpoint looked healthy.
No high-severity alert fired. No ransomware was detected. No incident was created.
But inside thousands of normal process events, one PowerShell EncodedCommand was waiting to be found.
The command was not hidden by encryption. It was hidden by noise.
Briefing summary
A workstation generated thousands of legitimate process events. Agent Foskett reviewed PowerShell activity inside DeviceProcessEvents and found a single EncodedCommand hidden amongst routine administration, software deployment and endpoint management noise.
What happened
The query that started the investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
DeviceProcessEvents | where Timestamp > ago(7d) | where FileName =~ "powershell.exe" | project Timestamp, DeviceName, InitiatingProcessFileName, ProcessCommandLine | order by Timestamp desc
One command looked different
- 1
- 2
- 3
- 4
- 5
- 6
- 7
powershell.exe -EncodedCommand SQBFAFgAKABOAGU... // nearby noise: Install-Module // nearby noise: Intune Management Extension // nearby noise: Defender remediation task // the suspicious command was just another row
Agent Foskett moment
Following the execution chain
What most environments miss
How defenders can investigate it
Related investigations
Final thought
A single EncodedCommand was buried inside thousands of process events. Explore related investigations including The PowerShell Command Was Base64 Encoded, The Child Process Shouldn't Have Existed, and The Process Tree Told The Real Story.
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD