logo

Prioritizing suspicious PowerShell activity with machine learning

ID: d15f9baf-7cc6-5e69-aa92-bdd2e7b1d78d

STIX ID: report--d15f9baf-7cc6-5e69-aa92-bdd2e7b1d78d

Feed Name: Expel Blog

Date Published: 2020-07-21

Date Updated: 2026-04-27

Author: Elisabeth Weber

...
...

Expel describes building and deploying a LightGBM machine-learning model to evaluate PowerShell process arguments and predict the likelihood an alert is malicious, integrating the model into an automated triage robot that can reprioritize (but not suppress) alerts in their SOC workflow; the post outlines model features (e.g., entropy, special character counts, indicators like "-enc"), operationalization details, and key lessons on production monitoring, human oversight, and analyst feedback.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.