logo

New PowerShell History Defense Evasion Technique

ID: b925b3a9-133b-5f2b-8850-4e873515079a

STIX ID: report--b925b3a9-133b-5f2b-8850-4e873515079a

Feed Name: Black Hills Infosec Blog

Date Published: 2022-11-29

Date Updated: 2026-04-27

Author: BHIS

...
...

This report explains a defense-evasion technique in PowerShell where PSReadLine can skip recording commands containing sensitive words (e.g., Password, Asplaintext, Token, Apikey, Secret) and shows how attackers can exploit this by inserting such words in comments or by configuring PSReadLine (e.g., disabling AddToHistoryHandler, setting HistorySaveStyle to SaveNothing, deleting or redirecting the history file, or using ConstrainedLanguage mode), with defensive guidance to watch for suspicious PSReadLineOption usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.