high closed true positive

๐Ÿท๏ธ Analyst Verdict Classification

FP by analyst

๐Ÿค– AI Analysis

๐Ÿ”” Detections (1)

Non Interactive PowerShell Process Spawned high
Rule: service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
Hostname: desktop-atsepsk ยท Sensor: 8f3a47be-5629-4c...
Event Type: NEW_PROCESS
Confidence: 0% ยท Verdict: true positive
Event Data:
BASE_ADDRESS:
1245184
COMMAND_LINE:
"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass Stop-Process -Force -Name remote_assistance_host_uiaccess
FILE_IS_SIGNED:
1
FILE_PATH:
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
HASH:
3bfedaaa40d9e19e45a3ee10c0f14b1750b01619ebb9f39be3865bcfdacdd2e5
MEMORY_USAGE:
36777984
PARENT:
{'BASE_ADDRESS': 1835008, 'COMMAND_LINE': 'C:\\Windows\\syswow64\\MsiExec.exe -Embedding 9E7BA15FECCFC4C86FC9AAF26C33912B E Global\\MSI0000', 'FILE_IS_SIGNED': 1, 'FILE_PATH': 'C:\\Windows\\syswow64\\MsiExec.exe', 'HASH': '34e2e75cb8622809e4f95b3e665071d755870f503167268f23d0110cc5f7ee2c', 'MEMORY_USAGE': 13856768, 'PARENT_ATOM': 'ad4f1df838ce809c153f27726a1f6436', 'PARENT_PROCESS_ID': 141408, 'PROCESS_ID': 142044, 'THIS_ATOM': 'b23113c3a733a70164c733386a1f6437', 'THREADS': 7, 'TIMESTAMP': 1780442166907, 'USER_NAME': 'NT AUTHORITY\\SYSTEM'}
PARENT_PROCESS_ID:
142044
PROCESS_ID:
127260
THREADS:
17
USER_NAME:
NT AUTHORITY\SYSTEM
Analyst Declaration:
๐Ÿ“„ Raw Detection JSON
{
  "author": "_ext-sigma-7a14fbc3-54d9-4b4d-8700-61eddada04f0[bulk][segment]",
  "cat": "Non Interactive PowerShell Process Spawned",
  "detect": {
    "event": {
      "BASE_ADDRESS": 1245184,
      "COMMAND_LINE": "\"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass Stop-Process -Force -Name remote_assistance_host_uiaccess",
      "FILE_IS_SIGNED": 1,
      "FILE_PATH": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe",
      "HASH": "3bfedaaa40d9e19e45a3ee10c0f14b1750b01619ebb9f39be3865bcfdacdd2e5",
      "MEMORY_USAGE": 36777984,
      "PARENT": {
        "BASE_ADDRESS": 1835008,
        "COMMAND_LINE": "C:\\Windows\\syswow64\\MsiExec.exe -Embedding 9E7BA15FECCFC4C86FC9AAF26C33912B E Global\\MSI0000",
        "FILE_IS_SIGNED": 1,
        "FILE_PATH": "C:\\Windows\\syswow64\\MsiExec.exe",
        "HASH": "34e2e75cb8622809e4f95b3e665071d755870f503167268f23d0110cc5f7ee2c",
        "MEMORY_USAGE": 13856768,
        "PARENT_ATOM": "ad4f1df838ce809c153f27726a1f6436",
        "PARENT_PROCESS_ID": 141408,
        "PROCESS_ID": 142044,
        "THIS_ATOM": "b23113c3a733a70164c733386a1f6437",
        "THREADS": 7,
        "TIMESTAMP": 1780442166907,
        "USER_NAME": "NT AUTHORITY\\SYSTEM"
      },
      "PARENT_PROCESS_ID": 142044,
      "PROCESS_ID": 127260,
      "THREADS": 17,
      "USER_NAME": "NT AUTHORITY\\SYSTEM"
    },
    "routing": {
      "arch": 2,
      "did": "",
      "event_id": "0a7cf509-c3ac-4d9c-8102-62d60b080978",
      "event_time": 1780442168489,
      "event_type": "NEW_PROCESS",
      "ext_ip": "23.128.32.10",
      "hostname": "desktop-atsepsk",
      "iid": "b2cd59fc-d09d-49e0-a9f2-1fd79ee9c175",
      "int_ip": "192.168.50.200",
      "latency": 476,
      "moduleid": 2,
      "oid": "d3541070-8b0e-4663-8a6a-aa0727aacd36",
      "parent": "b23113c3a733a70164c733386a1f6437",
      "plat": 268435456,
      "sid": "8f3a47be-5629-4c66-921d-17c39ed07e87",
      "tags": [
        "fusion-soc-alert",
        "fusion-soc-case",
        "fusion-soc-pulled",
        "fusion-soc-triage",
        "fusionsoc-critical",
        "fusionsoc-high",
        "fusionsoc-investigated",
        "joys",
        "windows",
        "yara_detection_memory"
      ],
      "this": "aa174f65888c6f41f9964be76a1f6438"
    }
  },
  "detect_id": "b202bd59-2fcc-4ca2-a812-3a526a1f6438",
  "detect_mtd": {
    "author": "Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements)",
    "description": "Detects non-interactive PowerShell activity by looking at the \"powershell\" process with a non-user GUI process such as \"explorer.exe\" as a parent.",
    "falsepositives": [
      "Likely. Many admin scripts and tools leverage PowerShell in their BAT or VB scripts which may trigger this rule often. It is best to add additional filters or use this to hunt for anomalies"
    ],
    "level": "low",
    "references": [
      "https://web.archive.org/web/20200925032237/https://threathunterplaybook.com/notebooks/windows/02_execution/WIN-190410151110.html"
    ],
    "tags": [
      "attack.execution",
      "attack.t1059.001"
    ]
  },
  "gen_time": 1780442168967,
  "link": "https://app.limacharlie.io/orgs/d3541070-8b0e-4663-8a6a-aa0727aacd36/sensors/8f3a47be-5629-4c66-921d-17c39ed07e87/timeline?time=1780442168\u0026selected=aa174f65888c6f41f9964be76a1f6438",
  "namespace": "general",
  "routing": {
    "arch": 2,
    "did": "",
    "event_id": "0a7cf509-c3ac-4d9c-8102-62d60b080978",
    "event_time": 1780442168489,
    "event_type": "NEW_PROCESS",
    "ext_ip": "23.128.32.10",
    "hostname": "desktop-atsepsk",
    "iid": "b2cd59fc-d09d-49e0-a9f2-1fd79ee9c175",
    "int_ip": "192.168.50.200",
    "latency": 476,
    "moduleid": 2,
    "oid": "d3541070-8b0e-4663-8a6a-aa0727aacd36",
    "parent": "b23113c3a733a70164c733386a1f6437",
    "plat": 268435456,
    "sid": "8f3a47be-5629-4c66-921d-17c39ed07e87",
    "tags": [
      "fusion-soc-alert",
      "fusion-soc-case",
      "fusion-soc-pulled",
      "fusion-soc-triage",
      "fusionsoc-critical",
      "fusionsoc-high",
      "fusionsoc-investigated",
      "joys",
      "windows",
      "yara_detection_memory"
    ],
    "this": "aa174f65888c6f41f9964be76a1f6438"
  },
  "rule_tags": [
    "ext:ext-sigma",
    "attack.execution",
    "attack.t1059.001"
  ],
  "source": "d3541070-8b0e-4663-8a6a-aa0727aacd36.b2cd59fc-d09d-49e0-a9f2-1fd79ee9c175.8f3a47be-5629-4c66-921d-17c39ed07e87.10000000.2",
  "source_rule": "service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution",
  "ts": 1780442170000
}
๐ŸŒ Threat Intel JSON
{
  "virustotal": {
    "malicious": false,
    "provider": "virustotal",
    "reputation": 0,
    "stats": {
      "confirmed-timeout": 0,
      "failure": 0,
      "harmless": 0,
      "malicious": 0,
      "suspicious": 0,
      "timeout": 11,
      "type-unsupported": 4,
      "undetected": 61
    }
  }
}
๐Ÿค– Triage JSON
{
  "confidence": 0.0,
  "false_positive_reason": null,
  "investigation_questions": [],
  "ioc_analysis": "",
  "iocs_extracted": [],
  "mitre_techniques": [],
  "recommended_actions": [
    "Manual analyst review required \u2014 AI models (majority)",
    "Manual review required"
  ],
  "risk_score": 50,
  "severity": "high",
  "summary": "**Vote: MAJORITY (1/1 -\u003e TRUE POSITIVE)**\n\n### \ud83e\udd16 qwen3.5:4b Analysis (Secondary)\nFailed or timed out.\n\n---\n\n### \ud83e\udd16 deepseek-r1:16b Analysis (Secondary)\nFailed or timed out.\n\n---\n\n### \ud83e\udd16 gemma3:4b Analysis (Secondary)\nFailed or timed out.",
  "verdict": "true_positive",
  "voting": {
    "auto_action": "manual_review",
    "mode": "majority",
    "total_models": 1,
    "vote_summary": [
      "qwen3.5:35b: true_positive (medium, 0% confidence)"
    ],
    "votes": [
      {
        "confidence": 0.0,
        "model": "qwen3.5:35b",
        "verdict": "true_positive"
      }
    ],
    "winning_count": 1,
    "winning_verdict": "true_positive"
  }
}

โš™๏ธ Response Actions

Action Target Status Result
tag 8f3a47be-5629-4c66-921d-17c39ed07e87:fusionsoc-investigated executed Tag applied
recommended Manual review required executed General Activity Sweep: 0 events found

๐Ÿ“ Add Note

๐Ÿ’ฌ Notes (3)

๐Ÿค– FusionSOC AI 2026-06-02T23:27
๐Ÿค– FusionSOC AI 2026-06-02T23:27
๐Ÿค– FusionSOC AI 2026-06-02T23:27

๐Ÿ“œ Timeline

2026-06-25T04:17:53
analyst
Status changed: investigating โ†’ closed
2026-06-25T04:17:50
analyst
Analyst classified as False Positive (FP)
2026-06-02T23:27:16
FusionSOC AI
Note by FusionSOC AI: ## ๐Ÿ—ณ๏ธ Secondary Vote (RAG-Enhanced) **Vote:** MAJORITY (1/1 โ†’ TRUE POSITIVE) - qwen3.5:35b: true_positive (medium, 0% c...
2026-06-02T23:27:16
FusionSOC AI
Status changed: open โ†’ investigating
2026-06-02T23:27:16
FusionSOC
Action recommended โ†’ executed: General Activity Sweep: 0 events found
2026-06-02T23:27:16
FusionSOC AI
Note by FusionSOC AI: ## ๐Ÿ” General Activity Sweep **Action:** Manual review required **Sensor:** `8f3a47be-5629-4c...` **Time Window:** +/- 2 ...
2026-06-02T23:27:16
FusionSOC
Response action queued: recommended on Manual review required
2026-06-02T23:27:16
FusionSOC
Action tag โ†’ executed: Tag applied
2026-06-02T23:27:15
FusionSOC
Response action queued: tag on 8f3a47be-5629-4c66-921d-17c39ed07e87:fusionsoc-investigated
2026-06-02T23:27:15
FusionSOC AI
Detection b202bd59-2fcc-4ca2-a812-3a526a1f6438 triaged as true_positive (medium severity, confidence: 0%)
2026-06-02T23:27:15
FusionSOC AI
Case created from detection: service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution