logo

PowerShell w/o PowerShell Simplified

ID: 644272b3-20fd-5bf2-bd58-2bfd1dc67444

STIX ID: report--644272b3-20fd-5bf2-bd58-2bfd1dc67444

Feed Name: Black Hills Infosec Blog

Date Published: 2018-03-01

Date Updated: 2026-04-27

Author: BHIS

...
...

This post presents a straightforward C# utility (prog.exe) that loads a PowerShell script from disk and invokes it using the System.Management.Automation Runspace API; it includes the full source, OS-/framework-specific compilation commands for Windows 7/10 (x86/x64), and instructions for embedding and running the target PowerShell function. The technique is explicitly framed as a way to bypass PowerShell restrictions and monitoring (and can sidestep some application whitelisting controls), and the author recommends stronger AWS/policy controls to mitigate abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.