Threat hunts for PowerShell
70 hunts covering PowerShell, each with a hypothesis, the queries that test it and what the hunt cannot see.
70 hunts
-
highResearch by Huntress
VPN Entry and Identity Harvest
An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.
5 query2 analytic1 checkpoint1 action2 taskcredential access · exfiltration · impact -
highResearch by Huntress
Microsoft Defender Antivirus Exclusion Abuse
An intruder has modified Microsoft Defender exclusions to shield malicious paths from scanning and enabled stealth settings to hide these changes from local administrators.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion -
high Part 2 of 2Research by Huntress
Web Worker Discovery and Payment Data Harvesting
An intruder is using a compromised IIS web worker to execute discovery tools and search for payment card data or database credentials.
3 query2 analytic2 checkpoint1 action2 taskcollection · discovery · execution -
high Part 1 of 2Research by Huntress
Web Shell Ingress and Platform Probing
An intruder has exploited a file upload vulnerability to drop web shells in member-facing directories after probing the application boundary and brute-forcing credentials.
3 query1 analytic1 checkpoint1 action2 taskcollection · discovery · execution -
highResearch by Cisco Talos
UAT-11587 Antino Backdoor Phased Infection and M365 C2
An adversary is using Cloudflare-hosted stagers to deliver the Rust-compiled Antino backdoor, which then establishes persistence via Run keys and communicates using Microsoft 365 as a dead-drop C2 channel.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Huntress
ChatGPT Custom GPT ClickFix Lure and MSI Installer
An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · initial access -
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Exfiltration and Impact
An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Persistence and AD Credential Harvesting
An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee Delivery and C2 Establishment
An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Sekoia
Contextual Investigation of Phased PowerShell Intrusions
An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
highResearch by Microsoft
NeedyMantis Modular Sideloading and WebSocket C2
An adversary has established long-term access by sideloading modular components into legitimate processes like Poedit or Vim, using encrypted archives staged in unusual directories to bypass detection.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Sekoia
Exvicy ClickFix Social Engineering and PowerShell Execution
An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.
4 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
medium Part 1 of 2Research by Cisco Talos
ClickFix Browser Injection and Extension Persistence
An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
highResearch by Sekoia
Gamaredon GammaLoad Intrusion Lifecycle
An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · persistence -
high Part 2 of 2Research by Sekoia
ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Sekoia
ErrTraffic Infrastructure and Delivery Monitoring
An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Cisco Talos
Amatera Stealer and Follow-on Payloads
An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Sekoia
Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration
An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 1 of 2Research by Sekoia
Gammasteel Fileless PowerShell Registry Staging
An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 2 of 2Research by Rapid7
Metasploit Lateral Movement and Native Persistence
An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 1 of 2Research by Rapid7
Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
highResearch by Sekoia
Gamaredon Modular Espionage Chain
An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-8088 -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Microsoft
Node.js Backdoor and Lateral Movement
An intruder is using a portable Node.js runtime and an obfuscated implant staged in LocalAppData to move laterally via WinRM after initial social engineering via Microsoft Teams.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Microsoft
IT Support Impersonation and Remote Access
An attacker has gained interactive access by impersonating IT support via Microsoft Teams, coaxing a user into initiating an RMM session that bypasses standard perimeter controls.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 2Research by The DFIR Report
Bumblebee Delivery and Persistence
An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · exfiltration -
high Part 3 of 3Research by The DFIR Report
Persistence and Exfiltration of Lunar Spider
An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.
4 query1 analytic1 checkpoint1 action2 taskCVE-2020-1472 -
critical Part 2 of 2Research by Huntress
Settra Ransomware Local Impact and Recovery Inhibition
An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 1 of 2Research by Huntress
Settra Persistence via MeshAgent and Remote Access
An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Sekoia
Gamaredon GammaLoad Multi-stage Persistence and Execution
An intruder has established persistent access using GammaLoad VBScripts that manage C2 configuration via registry keys in HKCU\Console and execute via a high-frequency task invoking an Alternate Data Stream.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
highResearch by Red Canary
Entra ID Agent User Impersonation and Teams Abuse
An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.
3 query1 analytic1 checkpoint1 action2 taskexecution · initial access -
highResearch by Elastic Security Labs
Bulk Directory Discovery via AAD Graph API
An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.
3 query2 analytic2 checkpoint1 action2 taskdiscovery · execution · initial access -
high Part 1 of 2Research by Sekoia
ErrTraffic: WordPress Infrastructure and Backdoor Maintenance
An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by Huntress
Malicious C2 Infrastructure Polling
An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.
5 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Huntress
Cross-Platform Malware Execution and Persistence
An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Huntress
AI-Impersonation Driven Script Execution and Data Theft
An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 1 of 2Research by Huntress
AI Platform Mediated Malvertising and Redirection
An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.
4 query1 analytic1 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 2 of 2Research by Huntress
Tampered Exodus Wallet Persistence and C2
An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Unit 42
Spring Ring: NTLM Relay and RAT C2
An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 2Research by Unit 42
Microsoft Teams Vishing and Malicious Payload Execution
An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 3 of 3Research by The DFIR Report
SystemBC C2 and WinSCP Exfiltration
An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 3Research by The DFIR Report
Identity-Based Lateral Movement and Credential Access
An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by The DFIR Report
EarthTime Trojan to Ransomware Reconnaissance
An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Microsoft
IT Support Impersonation and WinRM Lateral Expansion
An adversary has hijacked a remote-support session to execute PowerShell, use a portable Node.js runtime for C2, and expand laterally via WinRM to domain controllers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
mediumResearch by Elastic Security Labs
Abuse of Trusted System Binaries for Payload Delivery
An adversary is exploiting internet-facing applications to execute certutil.exe for proxying payload downloads, which are then launched via rare, encoded PowerShell script blocks.
3 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · initial access -
mediumResearch by Elastic Security Labs
AI Coding Agent Tool-Call Auditing
An AI agent operating under developer credentials is executing rare shell commands, accessing sensitive configuration files, or communicating with third-party MCP servers without explicit developer intent.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
highResearch by Red Canary
Entra ID Assistive Agent Impersonation
An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · exfiltration -
high Part 2 of 2Research by The DFIR Report
Interlock RAT C2 and RDP Lateral Movement
An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by The DFIR Report
Interlock RAT Endpoint Execution and Reconnaissance
An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
highResearch by Elastic Security Labs
ClickFix DLL Sideloading and Infostealer Injection
An adversary has deployed a ClickFix script to sideload a malicious library into a signed Microsoft binary, followed by hollowing a system process to run an infostealer and using a BYOVD driver to blind endpoint security.
5 query2 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
highResearch by Huntress
Abused Faronics Deploy and RMM Installation
An adversary has used a phishing lure to install a legitimately signed Faronics Deploy agent, then abused its remote script execution capabilities to deploy ScreenConnect and establish persistent access.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
highResearch by Elastic Security Labs
KREMLIN Loader and Malicious Browser Extension Forgery
An adversary is using multi-stage JavaScript loaders to install a persistent Node.js task that sideloads malware via SentinelOne to forge browser integrity checks and install malicious extensions.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Sekoia
PureCrypter Loader and Mallox Ransomware Execution
An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Sekoia
Mallox Ransomware MSSQL Authentication and Service Abuse
An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Sekoia
iClickFix: NetSupport RAT Execution and Persistence
An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Sekoia
iClickFix Web Redirection and Delivery
An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Red Canary
Abused RMM Infrastructure and Network Patterns
An adversary is using unauthorized remote monitoring and management (RMM) tools for command and control, detectable via rare DNS lookups to RMM domains and specific User-Agent strings.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 3Research by Cisco Talos
UAT-10147: Host Elevation and Evasion
An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 3Research by Cisco Talos
Web Exploit and Telemetry Theft (UAT-10147)
The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
highResearch by Sekoia
MuddyRot Custom Implant Lifecycle
An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Huntress
RMM Command and Control and Redundancy
An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Huntress
Rogue ScreenConnect Host Execution and Persistence
An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 3 of 3Research by Microsoft
TerminalFix Asynchronous Shell and Reverse Tunnel
An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 3Research by Microsoft
TerminalFix ClickFix Delivery and Automated Reconnaissance
An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery