Scarcity signals: Are rare activities red flags?
ID: 155c3a9f-bc02-5ba4-913e-c9c4d9efdb7d
STIX ID: report--155c3a9f-bc02-5ba4-913e-c9c4d9efdb7d
Feed Name: Cisco Talos
Cisco Talos analyzed 3.2M PowerShell network connection logs (June–Dec 2024) across 742 base domains and found that rarely contacted domains had higher odds of being malicious (OR 3.18; not statistically significant), with a notable case where malicious activity originated from the subdomain raw.githubusercontent.com under the otherwise common domain githubusercontent.com. Cross-process comparisons showed generally low malicious rates except for wscript.exe, which exhibited disproportionately more malicious domain contacts. Talos recommends prioritizing investigations on rare domains, performing subdomain-level and argument-based reviews, integrating manual validation to reduce false positives, and exploring temporal/behavioral analytics and composite risk scoring in future work.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
