logo

Scarcity signals: Are rare activities red flags?

ID: 155c3a9f-bc02-5ba4-913e-c9c4d9efdb7d

STIX ID: report--155c3a9f-bc02-5ba4-913e-c9c4d9efdb7d

Feed Name: Cisco Talos

Date Published: 2025-05-23

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos analyzed 3.2M PowerShell network connection logs (June–Dec 2024) across 742 base domains and found that rarely contacted domains had higher odds of being malicious (OR 3.18; not statistically significant), with a notable case where malicious activity originated from the subdomain raw.githubusercontent.com under the otherwise common domain githubusercontent.com. Cross-process comparisons showed generally low malicious rates except for wscript.exe, which exhibited disproportionately more malicious domain contacts. Talos recommends prioritizing investigations on rare domains, performing subdomain-level and argument-based reviews, integrating manual validation to reduce false positives, and exploring temporal/behavioral analytics and composite risk scoring in future work.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.