{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/system-reconnaissance/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["discovery","system-reconnaissance","powershell","applocker"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries often perform reconnaissance within a compromised environment to understand existing security controls before attempting to deploy secondary payloads or move laterally. A specific technique observed involves the use of native Windows PowerShell administrative cmdlets to query AppLocker policies. By executing the Get-AppLockerPolicy cmdlet with specific flags such as -Effective, -Ldap, or -Local, an attacker can determine which applications are permitted or blocked from execution. This information allows an adversary to tailor their subsequent execution techniques to bypass security restrictions or confirm if their target binaries are permitted to run. Defenders should monitor for these specific command-line patterns, as they often deviate from standard user activity and indicate preparation for further malicious activity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful reconnaissance enables an attacker to refine their post-exploitation strategy by identifying gaps in execution control, potentially leading to successful privilege escalation, persistence establishment, or execution of malicious tools that would otherwise be blocked.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to monitor for suspicious invocation of AppLocker policy cmdlets. Because this activity is common in administrative troubleshooting, focus initial implementation on baseline discovery before applying blocking or high-alerting thresholds. Enable PowerShell Script Block Logging (Event ID 4104) and Sysmon Process Creation (Event ID 1) to capture the required command-line telemetry.\u003c/p\u003e\n","date_modified":"2026-08-18T23:52:20Z","date_published":"2026-08-18T23:52:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-powershell-applocker-discovery/","summary":"Detection of adversarial reconnaissance activities leveraging the Get-AppLockerPolicy PowerShell cmdlet to map host-based application execution restrictions.","title":"PowerShell AppLocker Policy Discovery via Get-AppLockerPolicy","url":"https://feed.craftedsignal.io/briefs/2026-08-powershell-applocker-discovery/"}],"language":"en","title":"CraftedSignal Threat Feed - System-Reconnaissance","version":"https://jsonfeed.org/version/1.1"}