New PowerShell History Defense Evasion Technique
ID: b925b3a9-133b-5f2b-8850-4e873515079a
STIX ID: report--b925b3a9-133b-5f2b-8850-4e873515079a
Feed Name: Black Hills Infosec Blog
This report explains a defense-evasion technique in PowerShell where PSReadLine can skip recording commands containing sensitive words (e.g., Password, Asplaintext, Token, Apikey, Secret) and shows how attackers can exploit this by inserting such words in comments or by configuring PSReadLine (e.g., disabling AddToHistoryHandler, setting HistorySaveStyle to SaveNothing, deleting or redirecting the history file, or using ConstrainedLanguage mode), with defensive guidance to watch for suspicious PSReadLineOption usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
