Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
ID: 5665372c-b08a-5477-9989-899483723bf6
STIX ID: report--5665372c-b08a-5477-9989-899483723bf6
Feed Name: Detect FYI
Threat Score
This report examines unmanaged PowerShell execution—techniques where adversaries host the PowerShell runtime inside other processes (e.g., via PowerShdll and SharpPick) to evade detections—and demonstrates hunting/detection strategies using Elastic and Sysmon by looking for non-powershell processes loading System.Management.Automation.dll and abnormal PowerShell-related named pipe activity; it also highlights APT35 as a known actor using this tradecraft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
