nesrine cherrabi

THREAT HUNTER

Unmanaged PowerShell Execution: Hunting Beyond powershell.exe

Attackers increasingly run PowerShell without ever touching powershell.exe, loading the engine straight into other processes to slip past the obvious detections. This piece walks through hunting that unmanaged PowerShell execution in Elastic, with Sigma logic your SOC can put to work.

Continue reading on Medium →

Scroll to Top