{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/defensive-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["windows","powershell","detection","defensive-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAttackers frequently abuse the Windows API via PowerShell to execute code directly in memory, bypassing traditional file-based detection mechanisms. By leveraging methods such as VirtualAlloc, WriteProcessMemory, and CreateRemoteThread, actors can achieve process injection, while others use token manipulation (e.g., OpenProcessToken, AdjustTokenPrivileges) to escalate privileges or move laterally. These techniques are commonly associated with post-exploitation frameworks and manual hands-on-keyboard activity. This intelligence brief provides a detection-focused approach to identifying these patterns using PowerShell Script Block Logging, which is essential for visibility into de-obfuscated script content that would otherwise remain hidden from standard command-line telemetry.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for stealthy persistence, credential theft, and privilege escalation, often leading to full system compromise or lateral movement within a domain. The reliance on in-memory execution complicates forensic analysis and incident response.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should prioritize the implementation of PowerShell Script Block Logging to gain visibility into the code being executed by the PowerShell engine.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable PowerShell Script Block Logging (Event ID 4104) via Group Policy on all endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to your SIEM to monitor for known patterns of process injection and token theft.\u003c/li\u003e\n\u003cli\u003eEstablish baseline activity for administrative scripts that may utilize WinAPI calls to reduce false positives during the tuning phase.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:36:52Z","date_published":"2026-09-03T12:36:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-winapi-powershell/","summary":"Detection engineering brief covering the identification of malicious PowerShell scripts leveraging Windows API calls for process injection, token manipulation, and in-memory execution.","title":"Detection of Suspicious WinAPI Usage in PowerShell Scripts","url":"https://feed.craftedsignal.io/briefs/2026-09-winapi-powershell/"}],"language":"en","title":"CraftedSignal Threat Feed - Defensive-Security","version":"https://jsonfeed.org/version/1.1"}