Some PowerShell Goodies

12
PowerShell 10 reasons why it’s scary

Transcript of Some PowerShell Goodies

PowerShell

10 reasons why it’s scary

#10PowerShell is installed by default on all new Windows computers.

#9It can execute payloads directly from memory, making it stealthy.

#8It generates few traces by default, making it difficult to find under forensic analysis.

#7PowerShell has remote access capabilities by default with encrypted traffic.

#6As a script, it is easy to obfuscate and difficult to detect with traditional security tools.

#5PowerShell can bypass application-whitelisting tools depending on the configuration.

#4Many gateway sandboxes do not handle script-based malware well.

#3It has a growing community with ready available scripts.

#2Many system admins use and trust the framework, allowing PowerShell malware to blend in with regular administration work.

#1Defenders often overlook it when hardening their systems.

Fileless Malware: An Evolving Threat on the Horizon

In order to better protect your environment, it is critical to understand how attackers are manipulating these tools, and using them to gain access and create a launching pad for their malicious operation…

more