Active Compromise: PowerShell Post-Exploitation Chain
When PowerShell usage is detected in conjunction with a download cradle and external network connection correlation, C2 beacon suspicion, or a lateral movement chain — evidence collection in the correct order and controlled isolation take priority over speed.
IEX, DownloadString, and Base64 tokens generate high-confidence alerts. Before enabling Constrained Language Mode and AMSI, it must be verified that PowerShell v2 remnants have been removed from the environment.Prepare
5 steps- Notify IR Lead and CISO
Upon active compromise suspicion, immediately notify the IR Lead and security management; activate the war room or IR channel
- Legal preparation
If the incident has legal implications, initiate chain of custody; record all evidence collection steps with timestamps
- Prepare DFIR tools
Verify that WinPMem, Volatility3, and Velociraptor/KAPE tools are ready for deployment; check EDR live response authorization
- Inventory affected systems
Identify which hosts generated alerts via SIEM or EDR; assess parallel triage capacity for each host
- Verify logging and collection infrastructure
Confirm that `Microsoft-Windows-PowerShell/Operational`, Sysmon, and Security logs are being forwarded to the SIEM and that sufficient storage capacity is available