T1059.001 PowerShell — ATT&CK Technique
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems). PowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk. A number of PowerShell-based offensive testing tools are available, including Empire, PowerSploit, PoshC2, and PSAttack. PowerShell commands/scripts can also be executed without directly invoking the powershell.exe binary through interfaces to PowerShell's underlying System.Management.Automation assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).
Detection coverage (50)
- Potential APT FIN7 POWERHOLD Execution high
- Rorschach Ransomware Execution Activity critical
- Lace Tempest PowerShell Evidence Eraser high
- Potential POWERTRASH Script Execution high
- Lace Tempest PowerShell Launcher high
- Potential APT FIN7 Exploitation Activity medium
- Potential Exploitation of GoAnywhere MFT Vulnerability high
- Suspicious CrushFTP Child Process medium
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) high
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution high
- Remote Thread Creation Via PowerShell medium
- Uncommon PowerShell Hosts medium
- Network Connection Initiated By PowerShell Process low
- WinAPI Library Calls Via PowerShell Scripts medium
- bXOR Operator Usage In PowerShell Command Line - PowerShell Classic low
- Headless Process Launched Via Conhost.EXE medium
- WinAPI Function Calls Via PowerShell Scripts medium
- Unusually Long PowerShell CommandLine low
- Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace medium
- Potentially Suspicious PowerShell Child Processes medium
- Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace medium
- AWS EC2 Startup Shell Script Change high
- Change PowerShell Policies to an Insecure Level medium
- Exchange PowerShell Snap-Ins Usage high
- Suspicious PowerShell Download and Execute Pattern high
- Suspicious PowerShell Parameter Substring high
- Suspicious PowerShell Parent Process high
- PowerShell Script Run in AppData medium
- Net WebClient Casing Anomalies high
- Suspicious XOR Encoded PowerShell Command medium
- AppLocker Prevented Application or Script from Running medium
- Invoke-Obfuscation STDIN+ Launcher - Security high
- Invoke-Obfuscation Via Use Clip - Security high
- Invoke-Obfuscation VAR+ Launcher - Security high
- Invoke-Obfuscation Via Use MSHTA - Security high
- Invoke-Obfuscation Via Stdin - Security high
- Invoke-Obfuscation CLIP+ Launcher - Security high
- Invoke-Obfuscation RUNDLL LAUNCHER - Security medium
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security high
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security medium
- Invoke-Obfuscation Via Use Rundll32 - Security high
- Remote PowerShell Sessions Network Connections (WinRM) high
- Invoke-Obfuscation VAR+ Launcher - System high
- Invoke-Obfuscation Via Use MSHTA - System high
- Invoke-Obfuscation STDIN+ Launcher - System high
- Invoke-Obfuscation Via Use Clip - System high
- Invoke-Obfuscation Via Stdin - System high
- Invoke-Obfuscation COMPRESS OBFUSCATION - System medium
- Invoke-Obfuscation Via Use Rundll32 - System high
- Invoke-Obfuscation CLIP+ Launcher - System high
Malware using this technique
- TrickBot
- Bumblebee
- GRIFFON
- Bandook
- POWRUNER
- SharpStage
- Sardonic
- HALFBAKED
- TAMECAT
- PS1
- Ursnif
- RansomHub
- POWERSOURCE
- Tsundere Botnet
- Zeus Panda
- Havoc
- Prestige
- InvisibleFerret
- StrongPity
- Medusa Ransomware
- AppleSeed
- NETWIRE
- SQLRat
- LitePower
- PyDCrypt
- PowerExchange
- HAMMERTOSS
- Emotet
- BADHATCH
- PowerLess
- SystemBC
- Gootloader
- WellMess
- Woody RAT
- Mafalda
- Squirrelwaffle
- ShrinkLocker
- FlawedAmmyy
- Snip3
- DarkWatchman
- RegDuke
- WhisperGate
- TRANSLATEXT
- AADInternals
- PowerShower
- CHIMNEYSWEEP
- FatDuke
- GLASSTOKEN
- IPsec Helper
- PUNCHBUGGY
Threat actors using this technique
- Patchwork
- Inception
- Void Manticore
- Play Ransomware
- HEXANE
- Daggerfly
- WIRTE
- APT35
- APT38
- Evil Corp
- BlackByte
- GALLIUM
- APT3
- Kimsuky
- Volt Typhoon
- APT41
- Dragonfly
- Gorgon Group
- APT10
- APT32
- HAFNIUM
- MuddyWater
- FIN6
- APT-C-36
- Tonto Team
- GOLD SOUTHFIELD
- Gamaredon Group
- Gallmaker
- Storm-1811
- TeamTNT
- FIN7
- Sandworm Team
- CURIUM
- Mustang Panda
- Scattered Spider
- APT39
- UNC3886
- TA2541
- Akira
- OilRig
- TA459
- Aquatic Panda
- Saint Bear
- DarkHydrus
- Confucius
- APT40
- MoustachedBouncer
- Blue Mockingbird
- Winter Vivern
- Turla