CQL Hubby ByteRay
← All queries

Powershell Command Length Anomaly Detection

This query establishes a 7-day baseline of average PowerShell command lengths for each host. It then compares this baseline to the average command length of the last 24 hours. The query identifies hosts with a significant percentage increase in command length, which can be an indicator for obfuscation, fileless execution, or other malicious activities associated with "Living off the Land" techniques.

CQL · Falcon Next-Gen SIEMCopy query
Loading query…
Hunting_Powershell_Command_Length_Anomaly.yml
T1059.001, T1027.010
ByteRay GmbH
Detection
Endpoint
Insight

Want this running in your SIEM — with someone on call?

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team