Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
PowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.
A number of PowerShell-based offensive testing tools are available, including Empire, PowerSploit, PoshC2, and PSAttack.
PowerShell commands/scripts can also be executed without directly invoking the powershell.exe binary through interfaces to PowerShell's underlying System.Management.Automation assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).
Rules on DetectionCode tagged with T1059.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Any Powershell DownloadFile | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Any Powershell DownloadString | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| CrushFTP Authentication Bypass Exploitation | TTP | NULL | CrushFTP |
| Detect Certify With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Detect Empire with PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Detect Mimikatz With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Exchange PowerShell Module Usage | TTP | NULL | Powershell Script Block Logging 4104 |
| First time seen command line argument | Hunting | NULL | Sysmon EventID 1 |
| Get-ForestTrust with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| GetLocalUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| GetWmiObject User Account with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Malicious PowerShell Process - Execution Policy Bypass | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Malicious PowerShell Process With Obfuscation Techniques | TTP | NULL | Sysmon EventID 1 |
| Nishang PowershellTCPOneLine | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| PowerShell - Connect To Internet With Hidden Window | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| PowerShell 4104 Hunting | Hunting | NULL | Powershell Script Block Logging 4104 |
| Powershell COM Hijacking InprocServer32 Modification | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Creating Thread Mutex | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Defender Threat Actions Set to Allow | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| PowerShell Domain Enumeration | Anomaly | NULL | Powershell Script Block Logging 4104 |
| PowerShell Enable PowerShell Remoting | Anomaly | NULL | Powershell Script Block Logging 4104 |
| PowerShell Environment Variable Execution | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Powershell Execute COM Object | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Fileless Process Injection via GetProcAddress | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Fileless Script Contains Base64 Encoded Content | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Load Module in Meterpreter | TTP | NULL | Powershell Script Block Logging 4104 |
| PowerShell Loading DotNET into Memory via Reflection | Anomaly | NULL | Powershell Script Block Logging 4104 |
| PowerShell PInvoke Process Injection API Chain | TTP | NULL | Powershell Script Block Logging 4104 |
| Powershell Processing Stream Of Data | Anomaly | NULL | Powershell Script Block Logging 4104 |
| PowerShell Script Block With URL Chain | TTP | NULL | Powershell Script Block Logging 4104 |
| PowerShell Start or Stop Service | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Powershell Using memory As Backing Store | TTP | NULL | Powershell Script Block Logging 4104 |
| PowerShell WebRequest Using Memory Stream | TTP | NULL | Powershell Script Block Logging 4104 |
| Recon Using WMI Class | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Set Default PowerShell Execution Policy To Unrestricted or Bypass | TTP | NULL | Sysmon EventID 13 |
| Suspicious Powershell Command-Line Arguments | TTP | NULL | Sysmon EventID 1 |
| Unloading AMSI via Reflection | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Account Access Removal via Logoff Exec | Anomaly | NULL | Sysmon EventID 1 |
| Windows Cobalt Strike PowerShell Loader | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Content Copied from Browser was Executed | TTP | NULL | Sysmon EventID 13 AND Sysmon EventID 24 |
| Windows Crowdstrike RTR Script Execution | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Default Cobalt Strike PowerShell Beacon | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Enable PowerShell Web Access | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Explorer LNK Exploit Process Launch With Padding | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows Explorer.exe Spawning PowerShell or Cmd | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows File Download Via PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows MSExchange Management Mailbox Cmdlet Usage | Anomaly | NULL | |
| Windows Powershell Commands from DNS TXT | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Powershell Cryptography Namespace | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell FakeCAPTCHA Clipboard Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows PowerShell Get CIMInstance Remote Computer | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Powershell Import Applocker Policy | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Invoke-RestMethod IP Information Collection | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Invoke-Sqlcmd Execution | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows Powershell Logoff User via Quser | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Module File Created | Anomaly | NULL | Sysmon EventID 11 |
| Windows PowerShell MSIX Package Installation | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Process Implementing Manual Base64 Decoder | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerShell Process With Malicious String | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Powershell RemoteSigned File | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerShell ScheduleTask | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Script Block With Malicious String | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Script From WindowsApps Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerShell Script TabExpansion Direct Call | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell WMI Win32 ScheduledJob | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowGoop Beacon Decoding | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Shell Process from CrushFTP | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Software Discovery Via PowerShell | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows SSH Proxy Command | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Suspicious React or Next.js Child Process | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAkira | Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| GroupAPT19 | APT19 used PowerShell commands to execute payloads. |
| GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| GroupAPT3 | APT3 has used PowerShell on victim systems to download and run payloads after exploitation. |
| GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals is written and executed via PowerShell. |
| MalwareAkira | Akira will execute PowerShell commands to delete system volume shadow copies. |
| MalwareAppleSeed | AppleSeed has the ability to execute its payload via PowerShell. |
| MalwareAutoIt backdoor | AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| MalwareBADHATCH | BADHATCH can utilize `powershell.exe` to execute commands on a compromised host. |
| MalwareBandook | Bandook has used PowerShell loaders as part of execution. |
| MalwareBazar | Bazar can execute a PowerShell script received from C2. |
| MalwareBlack Basta | Black Basta has used PowerShell scripts for discovery and to execute files over the network. |
View all 131 software examples
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet |
| CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| CampaignFrankenstein | During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.