Auteur Sujet: [Trend]Proofs of Concept Abusing PowerShell Core: Caveats and Best Practices  (Lu 2948 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Proofs of Concept Abusing PowerShell Core: Caveats and Best Practices

We explored possible strategies attackers can employ when abusing PowerShell Core. These proofs of concept (PoCs) would help in better understanding — and in turn, detecting and preventing — the common routines and behaviors of possible and future threats that attackers might use. The PoCs we developed using PowerShell Core were conducted on Windows, Linux, and mac OSs. Most of the techniques we applied can be seen from previous threats involving PowerShell-based functionalities, such as the fileless KOVTER and POWMET. The scenarios in our PoCs are also based on the PowerShell function they use.


The post Proofs of Concept Abusing PowerShell Core: Caveats and Best Practices appeared first on .


Source: Proofs of Concept Abusing PowerShell Core: Caveats and Best Practices

Tags: