IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Why Do Some Powershell Events Show the .ps1 Script as the Process Name?

Carbon Black Cloud: Why Do Some Powershell Events Show the .ps1 Script as the Process Name?

Environment

  • Carbon Black Cloud Sensor: 3x
  • Microsoft Windows:  All Versions

Question

Why do some events in the Carbon Black console show PowerShell.exe as the process, and other events show the .ps1 script name as the process?

Answer

If both the Enterprise EDR (formerly known as Threat Hunter) and the Endpoint Standard (formerly known as Defense) features are enabled, this can/will occur.

The Endpoint Standard component of the sensor is designed to present the script name as the process when PowerShell runs a .ps1 file, in order to make it easier for a security analyst to see the behavior without drilling down into the event.

The Enterprise EDR (EEDR) component of the sensor does not perform the name replacement of the process like Endpoint Standard does. 

Additional Notes

As a workaround, add the following search term to the watchlist IOC/search to only show or not show the enhanced data:

Enhanced:true -- only show the events that have the PowerShell script name as the process
Enhanced:false -- only show the events that show PowerShell as the process.
 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-05-2022
Views:
1298
Contributors