Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
Attackers increasingly run PowerShell without ever touching powershell.exe, loading the engine straight into other processes to slip past the obvious detections. This piece walks through hunting that unmanaged PowerShell execution in Elastic, with Sigma logic your SOC can put to work.