Machine learning from idea to reality: a PowerShell case study
ID: e78325e2-2e79-5072-9f75-e9d577b41899
STIX ID: report--e78325e2-2e79-5072-9f75-e9d577b41899
Feed Name: Fox-IT blog
This blog post presents a case study by RIFT on detecting offensive and obfuscated PowerShell scripts using Windows Event Log 4104: it describes dataset construction (malicious scripts from GitHub, obfuscation datasets, and benign scripts), feature engineering based on token and character percentages, Random Forest models for obfuscation and offensive-script detection, evaluation results, and integration into Splunk for real-time detection; the authors recommend enabling PowerShell logging and iteratively improving the models for operational use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
