Circumventing EncodedCommand and IEX Detection in PowerShell
ID: aeefe134-bd86-52c6-a6a6-2ba15d5b502e
STIX ID: report--aeefe134-bd86-52c6-a6a6-2ba15d5b502e
Feed Name: TrustedSec blog
This report explains a PowerShell detection-evasion technique implemented in Unicorn 2.4: instead of using the literal -EncodedCommand/-ec switch (which defenders commonly flag), the payload constructs the string for the switch at runtime using set-variable and .value.toString(), then invokes the encoded payload; the write-up includes example commands, Unicorn output showing a staged Meterpreter reverse HTTPS session, and notes for defenders on what to monitor to detect this evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
