logo

Circumventing EncodedCommand and IEX Detection in PowerShell

ID: aeefe134-bd86-52c6-a6a6-2ba15d5b502e

STIX ID: report--aeefe134-bd86-52c6-a6a6-2ba15d5b502e

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report explains a PowerShell detection-evasion technique implemented in Unicorn 2.4: instead of using the literal -EncodedCommand/-ec switch (which defenders commonly flag), the payload constructs the string for the switch at runtime using set-variable and .value.toString(), then invokes the encoded payload; the write-up includes example commands, Unicorn output showing a staged Meterpreter reverse HTTPS session, and notes for defenders on what to monitor to detect this evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.