PowerShell w/o PowerShell Simplified
ID: 644272b3-20fd-5bf2-bd58-2bfd1dc67444
STIX ID: report--644272b3-20fd-5bf2-bd58-2bfd1dc67444
Feed Name: Black Hills Infosec Blog
This post presents a straightforward C# utility (prog.exe) that loads a PowerShell script from disk and invokes it using the System.Management.Automation Runspace API; it includes the full source, OS-/framework-specific compilation commands for Windows 7/10 (x86/x64), and instructions for embedding and running the target PowerShell function. The technique is explicitly framed as a way to bypass PowerShell restrictions and monitoring (and can sidestep some application whitelisting controls), and the author recommends stronger AWS/policy controls to mitigate abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
