Prioritizing suspicious PowerShell activity with machine learning
ID: d15f9baf-7cc6-5e69-aa92-bdd2e7b1d78d
STIX ID: report--d15f9baf-7cc6-5e69-aa92-bdd2e7b1d78d
Feed Name: Expel Blog
Expel describes building and deploying a LightGBM machine-learning model to evaluate PowerShell process arguments and predict the likelihood an alert is malicious, integrating the model into an automated triage robot that can reprioritize (but not suppress) alerts in their SOC workflow; the post outlines model features (e.g., entropy, special character counts, indicators like "-enc"), operationalization details, and key lessons on production monitoring, human oversight, and analyst feedback.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
