Netskope Threat Labs

APP-DETECT Outgoing request from PowerShell detected

IPS-SWG

1 SID: 151031

Detects outgoing HTTP requests whose user agent identifies the Windows PowerShell interpreter (WindowsPowerShell). Administrators generate this traffic during routine management, but malware also abuses PowerShell to download payloads and to communicate with command and control servers, so the signature tags the activity for investigation (MITRE ATT&CK T1059.001).

No cross-references or related blog posts found for this signature.