- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-09-2026 07:06 PM
I just received this alert "Powershell Activity - 2390140751
" with this description "Suspicious script with keywords written in a non-standard way." in Cortex multiple times related to PowerShell script execution on a developer machine. The executed scripts were different and I don't know why Cortex is blocking such executions. There is also no documentation on this.
08-10-2026 11:16 AM
Hello @N.Patel578121 ,
Greetings for the day.
The “Powershell Activity - 2390140751” alert is triggered by the BTP rule bioc.suspicious_powershell_obfuscation_backtick, which detects PowerShell scripts using obfuscation or backticks that may be used to bypass security controls.
Resolution:
This approach avoids broadly disabling the BTP protection while allowing legitimate PowerShell activity.
Or Create a TAC Support ticket for the latest update on this.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

