Powershell Command Length Anomaly Detection
This query establishes a 7-day baseline of average PowerShell command lengths for each host. It then compares this baseline to the average command length of the last 24 hours. The query identifies hosts with a significant percentage increase in command length, which can be an indicator for obfuscation, fileless execution, or other malicious activities associated with "Living off the Land" techniques.
CQL · Falcon Next-Gen SIEMCopy query
Loading query…Hunting_Powershell_Command_Length_Anomaly.yml
T1059.001, T1027.010
ByteRay GmbH
Detection
Endpoint
Insight
