{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/t1059.001/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["windows","powershell","detection","T1059.001"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis detection analytic targets the execution of offensive security toolkits commonly used by adversaries to facilitate post-exploitation activities such as credential theft, lateral movement, and persistence. By analyzing process execution telemetry (including Event ID 4688 or Sysmon Event ID 1) mapped to the Endpoint data model, the detection flags PowerShell command-line arguments that match known malicious patterns. This approach is instrumental for identifying unauthorized access and privilege escalation attempts. The analytic supports organizations in identifying activities related to well-known offensive frameworks, including PowerSploit, PowerShell Empire, and PowerSharpPack, by leveraging lookups of known malicious string indicators within command execution logs.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn adversary gains initial access to a target Windows endpoint.\u003c/li\u003e\n\u003cli\u003eThe adversary executes a PowerShell command directly via command-line or via a wrapper process.\u003c/li\u003e\n\u003cli\u003eThe PowerShell process logs the full command-line string through security logging mechanisms.\u003c/li\u003e\n\u003cli\u003eSecurity telemetry (Sysmon or Windows Security Events) captures the process creation event.\u003c/li\u003e\n\u003cli\u003eThe detection engine ingests process telemetry and maps it to the Endpoint data model.\u003c/li\u003e\n\u003cli\u003eThe system performs a lookup against a curated list of known offensive PowerShell strings.\u003c/li\u003e\n\u003cli\u003eIf a match is identified, a security alert is generated for analyst investigation into potential lateral movement or credential theft.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these techniques allows adversaries to execute arbitrary code, steal sensitive credentials, move laterally within the network, and establish long-term persistence on compromised endpoints. If left undetected, this can lead to full system compromise and exfiltration of sensitive organizational data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the analytic search to your SIEM to monitor for known malicious PowerShell strings.\u003c/li\u003e\n\u003cli\u003eEnsure Windows Event Log (4688) or Sysmon (Event ID 1) telemetry is enabled and correctly mapped to the CIM Endpoint data model.\u003c/li\u003e\n\u003cli\u003eIngest full command-line executions to allow for accurate string matching against known offensive toolkits.\u003c/li\u003e\n\u003cli\u003eReview the findings generated by the analytic to investigate potential unauthorized activity on endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T12:25:59Z","date_published":"2026-10-05T12:25:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-malicious-powershell-detection/","summary":"This detection analytic identifies suspicious PowerShell activity by monitoring command-line strings for patterns associated with known offensive security toolkits used for credential theft, lateral movement, and persistence.","title":"Detection of Malicious PowerShell Command-Line Patterns","url":"https://feed.craftedsignal.io/briefs/2026-10-malicious-powershell-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - T1059.001","version":"https://jsonfeed.org/version/1.1"}