T1059.001ExecutionAdvanced
Covers PowerShell's Windows logging architecture (EID 4104 Script Block, EID 4103 Module, Transcription, EID 400 downgrade detection) and the AMSI infrastructure from an attack perspective. AMSI bypass families (AmsiScanBuffer patching, amsiContext manipulation, VEH patchless, obfuscation), PSv2 downgrade, and download cradles are addressed in the Exploit & POC section; behavioral Sigma rules and a correlation schema in Detection; mandatory GPO configuration, CLM/WDAC, PSv2 removal, and WEF centralized collection in Prevention.
17 min read
Exploit
Prevention
Detection