logo

Unmanaged PowerShell Execution: Hunting Beyond powershell.exe

ID: 5665372c-b08a-5477-9989-899483723bf6

STIX ID: report--5665372c-b08a-5477-9989-899483723bf6

Feed Name: Detect FYI

Threat Score
60/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Nesrine Cherrabi

...
...

This report examines unmanaged PowerShell execution—techniques where adversaries host the PowerShell runtime inside other processes (e.g., via PowerShdll and SharpPick) to evade detections—and demonstrates hunting/detection strategies using Elastic and Sysmon by looking for non-powershell processes loading System.Management.Automation.dll and abnormal PowerShell-related named pipe activity; it also highlights APT35 as a known actor using this tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.