PowerShell Security Best Practices
ID: 773b83be-a089-5270-a582-57028309bb0e
STIX ID: report--773b83be-a089-5270-a582-57028309bb0e
Feed Name: ReliaQuest Blog
This blog reviews how attackers leverage PowerShell for reconnaissance, persistence, and lateral movement, summarizes common PowerShell-based bypass techniques (in-memory execution, obfuscation, signed-binary proxy execution, AMSI bypasses, whitelisting workarounds), and provides defensive recommendations—Constrained Language Mode, AppLocker/WDAC, transcript/scriptblock/module/protected logging, JEA, AMSI, DSC, and EDR—while advising to block or monitor System.Management.Automation.dll and improve logging and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
