Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Execution

T1059.001 PowerShell

Sub-technique of T1059 Command and Scripting Interpreter

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 40.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.