<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PowerShell detected as Malware in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4729365#M7178</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/547768"&gt;@Troja007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2022 20:55:34 GMT</pubDate>
    <dc:creator>Hellen Queiros Brito</dc:creator>
    <dc:date>2022-11-28T20:55:34Z</dc:date>
    <item>
      <title>PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4649480#M6965</link>
      <description>&lt;P&gt;For a long time I received many alerts about the Powershell being indentified as Malware, when a retrospective Malware alert was received making that file as Clean.&lt;/P&gt;&lt;P&gt;Common detecion:&amp;nbsp;&lt;SPAN&gt;W32.PowershellEncodedBuffer.ioc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Did anyone else see this same behavior?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 12:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4649480#M6965</guid>
      <dc:creator>Hellen Queiros Brito</dc:creator>
      <dc:date>2022-07-13T12:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4651076#M6982</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1377376"&gt;@Hellen Queiros Brito&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;FYI, the IOC does not outline that Powershell itself is malware, it outlines that something malicious may has been done with powershell. This IOC has been seen often in the past. It outlines, in most cases, that the command line includes a base64 encoded string. This technique can be used to hide something. This technique is also described by MITRE to obfuscate something.&lt;/P&gt;
&lt;P&gt;Two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;i assume the IOC shows a severity level low, right?&lt;/LI&gt;
&lt;LI&gt;The IOC should also outline the string which was encoded, right?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 09:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4651076#M6982</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-07-15T09:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4728247#M7175</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/547768"&gt;@Troja007&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it's right. Shows as severety level low and it's was encoded too.&lt;/P&gt;&lt;P&gt;and what can we do in this case, I still receive several alerts regarding the PS and in another topic on the cisco blog it was mentioned that an isolated case would not be serious, but several alerts would already become worrying, relating to cases of LOLBins&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help!!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 19:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4728247#M7175</guid>
      <dc:creator>Hellen Queiros Brito</dc:creator>
      <dc:date>2022-11-25T19:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4728953#M7176</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/844356"&gt;@hell&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;there are two options.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Short Term: You may open a TAC case, so an exclusion gets added to your environment.&lt;/LI&gt;
&lt;LI&gt;Mid Term: We will provide IOC exclusions soon, so customer can configure their own IOC exclusions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 08:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4728953#M7176</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-11-28T08:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4729365#M7178</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/547768"&gt;@Troja007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 20:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4729365#M7178</guid>
      <dc:creator>Hellen Queiros Brito</dc:creator>
      <dc:date>2022-11-28T20:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: PowerShell detected as Malware</title>
      <link>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4729572#M7179</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1377376"&gt;@Hellen Queiros Brito&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;FYI, custom CloudIOC exclusions have been released. They are handled and configured in the same way as any other exclusions.&lt;BR /&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/powershell-detected-as-malware/m-p/4729572#M7179</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-11-29T09:36:18Z</dc:date>
    </item>
  </channel>
</rss>

