Shells in Plain Sight - Storing Payloads in the Cloud
ID: 6eeb1454-87cf-5ab1-85cb-e1956fb0ee89
STIX ID: report--6eeb1454-87cf-5ab1-85cb-e1956fb0ee89
Feed Name: TrustedSec blog
This blog-style technical writeup demonstrates a proof-of-concept for hiding PowerShell shells inside PNG image pixels (using RED/ALPHA channels), hosting the manipulated images on public services (Twitter, Wikimedia), and retrieving/executing the payload with a PowerShell decoder. The post includes encoder/decoder code, a delimiter scheme, discussion of limitations (file format, image size, visibility), and suggestions to make detection harder, while noting that EDR and Invoke-Expression usage remain detection risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
