{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ingestion/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["windows","powershell","command-and-control","ingestion"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAttackers frequently leverage PowerShell to perform ingress tool transfers, moving malware or post-exploitation tooling from external systems into a compromised environment. By utilizing native system administration utilities, actors attempt to blend in with legitimate automation and maintenance tasks. This threat activity involves PowerShell processes making network connections for DNS resolution to identify remote resources, followed by the creation of potentially malicious files on the local filesystem.\u003c/p\u003e\n\u003cp\u003eDefenders should prioritize monitoring for PowerShell execution that culminates in file creation events, specifically when the domain resolution does not align with known trusted services (e.g., Microsoft update endpoints, standard package managers, or internal infrastructure). Given the prevalence of PowerShell in administrative routines, effective detection requires correlation between network events (DNS lookups) and file system events, combined with contextual filtering to suppress benign administrative activity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes initial access or presence on a target Windows host.\u003c/li\u003e\n\u003cli\u003eAttacker launches PowerShell or PowerShell ISE to facilitate file retrieval.\u003c/li\u003e\n\u003cli\u003ePowerShell performs a DNS query to resolve a remote, untrusted, or attacker-controlled domain.\u003c/li\u003e\n\u003cli\u003eThe network connection is successfully established to the resolved IP address.\u003c/li\u003e\n\u003cli\u003eThe PowerShell process invokes download commands (e.g., Invoke-WebRequest, IEX) to fetch the payload.\u003c/li\u003e\n\u003cli\u003ePowerShell writes the retrieved content to the disk (e.g., an .exe, .dll, or .ps1 file).\u003c/li\u003e\n\u003cli\u003eThe file creation event is logged by the system, identifying the PowerShell process as the actor.\u003c/li\u003e\n\u003cli\u003eAttacker subsequently executes the downloaded file to advance their objective, such as persistence or lateral movement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful ingress tool transfer allows attackers to introduce secondary malware, backdoors, or credential harvesting tools into a network. This facilitates long-term persistence, lateral movement, and data exfiltration. If left undetected, this activity provides the attacker with a platform to expand their footprint across the organization's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided Sigma detection rule to monitor for PowerShell-initiated downloads.\u003c/li\u003e\n\u003cli\u003eBaseline your environment's PowerShell usage to identify legitimate update or automation domains that should be added to the exclusion list.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon or Elastic Defend to capture both network (DNS) and file creation events, ensuring process-level lineage is available for investigation.\u003c/li\u003e\n\u003cli\u003eUse the provided investigation guide to analyze the parent process tree, examine digital signatures, and assess the reputation of external domains identified in the DNS logs.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-31T23:52:50Z","date_published":"2026-08-31T23:52:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-powershell-remote-download/","summary":"Detection of attackers using PowerShell to download executable, script, or library files from untrusted remote domains as part of command and control activity.","title":"Detecting PowerShell-Based Ingress Tool Transfers","url":"https://feed.craftedsignal.io/briefs/2026-08-powershell-remote-download/"}],"language":"en","title":"CraftedSignal Threat Feed - Ingestion","version":"https://jsonfeed.org/version/1.1"}