Turned out it is indeed one of our scheduled scripts we got from the community and we’re using it in our policies across all assets, it’s “Find Malicious Chrome Extensions” and this is the log for the script on the target machine giving this alert.
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
error> The term 'ConvertFrom-Json' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is c
error> orrect and try again.
error> At C:\ProgramData\Syncro\bin\ac713221-fb04-4479-9bb3-56b0cbef9552.ps1:14 char:56
error> + Get-Content $_.FullName -Raw | ConvertFrom-Json <<<< | select @{n='ComputerName';e={$ComputerName}}, @{n='User';e={$Matches[1]}}, Name, Version, @{n='Path';e={$path}}
error> + CategoryInfo : ObjectNotFound: (ConvertFrom-Json:String) [], CommandNotFoundException
error> + FullyQualifiedErrorId : CommandNotFoundException
error>
Found Malicious Plugin
Call-KabutoApi: success
Timed out (00:10:00).