logo

PowerShell Security Best Practices

ID: 773b83be-a089-5270-a582-57028309bb0e

STIX ID: report--773b83be-a089-5270-a582-57028309bb0e

Feed Name: ReliaQuest Blog

Threat Score
50/100

Date Published: 2019-10-08

Date Updated: 2026-04-29

...
...

This blog reviews how attackers leverage PowerShell for reconnaissance, persistence, and lateral movement, summarizes common PowerShell-based bypass techniques (in-memory execution, obfuscation, signed-binary proxy execution, AMSI bypasses, whitelisting workarounds), and provides defensive recommendations—Constrained Language Mode, AppLocker/WDAC, transcript/scriptblock/module/protected logging, JEA, AMSI, DSC, and EDR—while advising to block or monitor System.Management.Automation.dll and improve logging and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.