PageSourceSearch

https://www.veil-framework.com/component---src-components-page-tem…rshell-payloads-mdx-6bb3642f994aa89b3fe8.js

js veil-framework.com collected 2026-10-03 20:41:37 UTC 15,415 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkveil_framework=self.webpackChunkveil_framework||[]).push([[8520],{2422:function(e,t,n){n.r(t),n.d(t,{Head:function(){return f},default:function(){return h}});var a=n(8453),l=n(6540);function r(e){const t=Object.assign({h1:"h1",p:"p",h2:"h2",a:"a",ul:"ul",li:"li",code:"code",ol:"ol",strong:"strong"},(0,a.RP)(),e.components);return l.createElement(l.Fragment,null,l.createElement(t.h1,null,"PowerShell Payloads in Security Testing"),"\n",l.createElement(t.p,null,"PowerShell occupies a unique position in security testing. It is both the most powerful administrative tool in Windows environments and one of the most commonly abused attack surfaces. This page examines PowerShell-based payloads from both the offensive and defensive perspective, covering execution policies, logging, detection mechanisms, and the organizational controls that make PowerShell safer."),"\n",l.createElement(t.p,null,"Understanding how PowerShell payloads work is not an academic exercise — if you have ever triaged an incident involving fileless malware or living-off-the-land techniques, you know that PowerShell knowledge is a prerequisite for effective defense."),"\n",l.createElement(t.h2,null,"Why PowerShell Matters for Testing"),"\n",l.createElement(t.p,null,"PowerShell is pre-installed on every modern Windows system. It has deep access to .NET, WMI, COM objects, and Windows APIs. It can execute entirely in memory without writing files to disk. And until relatively recently, most organizations had minimal logging for PowerShell activity."),"\n",l.createElement(t.p,null,"These characteristics make PowerShell-based payloads an essential part of evasion testing. If your detection stack cannot see PowerShell misuse, you have a significant gap — one that real adversaries are already exploiting."),"\n",l.createElement(t.h2,null,"Execution Policies"),"\n",l.createElement(t.p,null,"PowerShell's execution policy is often misunderstood as a security boundary. It is not. Execution policy is a safety feature to prevent accidental script execution, not a security control. It can be bypassed through multiple methods that do not require administrative privileges."),"\n",l.createElement(t.p,null,"Organizations should understand that execution policy alone does not prevent malicious PowerShell activity. It needs to be part of a layered approach that includes logging, AMSI, and constrained language mode."),"\n",l.createElement(t.p,null,"For a complete reference on execution policies, their scope levels, and configuration options, ",l.createElement(t.a,{href:"https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies"},"Microsoft Learn's execution policy documentation")," covers the technical details and administrative guidance."),"\n",l.createElement(t.h2,null,"Script Block Logging"),"\n",l.createElement(t.p,null,"Script block logging (Event ID 4104) is the single most important PowerShell monitoring capability. When enabled, it records the full text of every PowerShell script block that executes — including dynamically generated code and decoded payloads."),"\n",l.createElement(t.p,null,"To enable script block logging:"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,"Group Policy path: Computer Configuration → Administrative Templates → Windows Components → Windows PowerShell → Turn on PowerShell Script Block Logging"),"\n",l.createElement(t.li,null,"Registry: ",l.createElement(t.code,null,"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\PowerShell\\ScriptBlockLogging")),"\n"),"\n",l.createElement(t.p,null,"Without script block logging, PowerShell-based attacks are effectively invisible to your SIEM. Enabling it is a high-impact, low-effort defensive improvement."),"\n",l.createElement(t.h2,null,"AMSI (Antimalware Scan Interface)"),"\n",l.createElement(t.p,null,"AMSI provides real-time inspection of PowerShell content before execution. When a script or command is entered, AMSI sends the content to the registered antimalware provider for scanning. This catches many known malicious patterns even when the script is obfuscated or dynamically assembled."),"\n",l.createElement(t.p,null,"However, AMSI bypass techniques exist and are actively researched. Testing your AMSI implementation against current bypass methods is a valid use of evasion testing — if your AMSI can be trivially bypassed, you need additional controls."),"\n",l.createElement(t.h2,null,"Constrained Language Mode"),"\n",l.createElement(t.p,null,"PowerShell Constrained Language Mode (CLM) restricts the language elements available in a PowerShell session. Under CLM, scripts cannot access .NET types, COM objects, or other advanced features that are commonly used in attacks. CLM is typically enforced through AppLocker or WDAC policies."),"\n",l.createElement(t.p,null,"CLM is one of the most effective defenses against PowerShell-based attacks because it removes the capabilities that make PowerShell attractive to attackers. Testing whether your CLM enforcement is complete and consistent across your environment is a valuable exercise."),"\n",l.createElement(t.h2,null,"Defensive Recommendations for Organizations"),"\n",l.createElement(t.p,null,"If you are responsible for PowerShell security in your organization:"),"\n",l.createElement(t.ol,null,"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Enable script block logging everywhere.")," This is non-negotiable for any organization that takes security monitoring seriously."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Enable module logging")," for additional visibility into cmdlet usage."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Deploy CLM")," through AppLocker or WDAC for standard users who do not need full PowerShell capabilities."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Forward PowerShell events")," to your SIEM with high priority."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Baseline normal PowerShell usage")," so you can identify anomalous activity."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Test your controls regularly")," with tools like the Veil Framework to verify detection coverage."),"\n"),"\n",l.createElement(t.h2,null,"Related"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/framework/veil-evasion/"},"Veil-Evasion"))," — Payload generation including PowerShell-based options"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/veil-command-line-usage/"},"Command-Line Usage"))," — Framework CLI reference"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/veil-powerview-usage-guide/"},"PowerView Usage Guide"))," — AD enumeration via PowerShell"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/guides/"},"Guides"))," — All available guides"),"\n"))}var i=function(e={}){const{wrapper:t}=Object.assign({},(0,a.RP)(),e.components);return t?l.createElement(t,e,l.createElement(r,e)):r(e)},o=n(9329),s=n(1744),c=n(8963),m=n(8752),u=n(7304);function d(e){if(!e)return null;try{return new Intl.DateTimeFormat("en-GB",{day:"numeric",month:"long",year:"numeric",timeZone:"UTC"}).format(new Date(e))}catch{return null}}function p({pageContext:e,children:t}){const{frontmatter:n}=e,a=(null==n?void 0:n.title)||"",r=(null==n?void 0:n.description)||"",i=(null==n?void 0:n.slug)||"",s=(null==n?void 0:n.heroImage)||null,p=(null==n?void 0:n.date)||null,h=(null==n?void 0:n.lastmod)||null,f=d(p),g=h&&h!==p?d(h):null;return l.createElement(o.A,null,s&&l.createElement(c.A,{title:a,subtitle:r,backgroundImage:s}),l.createElement("article",{className:"page-content"},l.createElement("div",{className:"container"},f&&l.createElement("p",{className:"post-meta"},l.createElement("time",{dateTime:p},"Published ",f),g&&l.createElement(l.Fragment,null," · ",l.createElement("time",{dateTime:h}
1,"Updated ",g))),l.createElement("div",{className:"post-layout-grid"},l.createElement("div",{className:"post-main"},t),l.createElement("aside",{className:"post-sidebar","aria-label":"Sidebar"},l.createElement("div",{className:"post-sidebar-scroll"},l.createElement(u.A),l.createElement(m.A,{sourceUrl:i})))))))}function h(e){return l.createElement(p,e,l.createElement(i,e))}function f({pageContext:e}){const{frontmatter:t}=e,n=null!=t&&t.heroImage?`https://www.veil-framework.com${t.heroImage}`:null;return l.createElement(s.A,{title:null==t?void 0:t.title,description:null==t?void 0:t.description,pathname:null==t?void 0:t.slug},(null==t?void 0:t.date)&&l.createElement("meta",{property:"article:published_time",content:t.date}),(null==t?void 0:t.lastmod)&&l.createElement("meta",{property:"article:modified_time",content:t.lastmod}),n&&l.createElement("meta",{property:"og:image",content:n}),n&&l.createElement("meta",{name:"twitter:image",content:n}))}},7304:function(e,t,n){n.d(t,{A:function(){return r}});var a=n(6540);function l({href:e,children:t,className:n,...l}){return a.createElement("a",Object.assign({href:e,target:"_blank",rel:"sponsored nofollow noopener",className:n},l),t)}function r(){const e="/veil-recommends/infosec-fundamentals";return a.createElement("aside",{className:"fc-wrap","aria-label":"Recommended course"},a.createElement("div",{className:"fc-header"},a.createElement("span",{className:"fc-dot fc-dot-r","aria-hidden":"true"}),a.createElement("span",{className:"fc-dot fc-dot-a","aria-hidden":"true"}),a.createElement("span",{className:"fc-dot fc-dot-g","aria-hidden":"true"}),a.createElement("span",{className:"fc-header-label"},"course_spotlight.sh")),a.createElement(l,{href:e,className:"fc-image-link","aria-label":"View Information Security Fundamentals course"},a.createElement("img",{src:"/img/hero/infosec-fundamentals.webp",alt:"Information Security Fundamentals course cover",className:"fc-image",loading:"lazy",width:"300",height:"169"})),a.createElement("div",{className:"fc-body"},a.createElement("div",{className:"fc-tag"},"Recommended Course"),a.createElement("h3",{className:"fc-title"},a.createElement(l,{href:e,className:"fc-title-link"},"Information Security Fundamentals")),a.createElement("p",{className:"fc-desc"},"Build a solid foundation in cybersecurity. Covers network fundamentals, common attack vectors, defensive controls, and the mindset needed for security research."),a.createElement("ul",{className:"fc-features"},a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"▸"),"Beginner-friendly — no prior experience needed"),a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"▸"),"Network attacks & defences"),a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"▸"),"Real-world security concepts")),a.createElement(l,{href:e,className:"fc-cta"},"View Course",a.createElement("span",{className:"fc-cta-arrow","aria-hidden":"true"}," →")),a.createElement("p",{className:"fc-disclosure"},"We may earn a commission if you enrol via our link, at no extra cost to you.")))}},8453:function(e,t,n){n.d(t,{RP:function(){return r}});var a=n(6540);const l=a.createContext({});function r(e){const t=a.useContext(l);return a.useMemo(()=>"function"==typeof e?e(t):{...t,...e},[t,e])}},8752:function(e,t,n){n.d(t,{A:function(){return l}});var a=n(6540);function l({sourceUrl:e}){const{0:t,1:n}=(0,a.useState)("idle"),{0:l,1:r}=(0,a.useState)("");return a.createElement("aside",{className:"nl-sw-wrap","aria-label":"Newsletter signup"},a.createElement("div",{className:"nl-sw-header"},a.createElement("span",{className:"nl-sw-dot nl-sw-dot-r","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-dot nl-sw-dot-a","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-dot nl-sw-dot-g","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-title"},"intel_feed.sh")),a.createElement("div",{className:"nl-sw-body"},a.createElement("p",{className:"nl-sw-prompt"},a.createElement("span",{className:"nl-sw-caret","aria-hidden":"true"},"$")," ","subscribe --to evasion-intel"),a.createElement("h3",{className:"nl-sw-heading"},"Stay ahead of the curve"),a.createElement("p",{className:"nl-sw-desc"},"AV bypass techniques, detection gaps, and lab-tested research — delivered before the mainstream catches up."),"done"===t?a.createElement("div",{className:"nl-sw-success",role:"status"},a.createElement("span",{className:"nl-sw-check","aria-hidden":"true"},"✓"),a.createElement("div",null,a.createElement("strong",null,"Subscribed."),a.createElement("br",null),a.createElement("span",{className:"nl-sw-success-sub"},"Confirm your email to activate."))):a.createElement("form",{onSubmit:async function(e){e.preventDefault();const t=e.currentTarget,a=new FormData(t);
1if(!a.get("company")){n("loading"),r("");try{const e=await fetch("/api/subscribe",{method:"POST",body:a}),l=await e.json();l.success?(n("done"),t.reset()):(n("err"),r(l.error||"Something went wrong."))}catch{n("err"),r("Network error — please try again.")}}},className:"nl-sw-form",noValidate:!0},a.createElement("input",{type:"hidden",name:"site",value:"veil-framework"}),a.createElement("input",{type:"hidden",name:"source_url",value:e||""}),a.createElement("input",{type:"text",name:"company",tabIndex:"-1","aria-hidden":"true",className:"nl-sw-hp",autoComplete:"off"}),a.createElement("label",{htmlFor:"nl-sw-name",className:"nl-sw-label"},"Your name"),a.createElement("input",{id:"nl-sw-name",type:"text",name:"name",placeholder:"alias or handle",required:!0,autoComplete:"given-name",className:"nl-sw-input",disabled:"loading"===t}),a.createElement("label",{htmlFor:"nl-sw-email",className:"nl-sw-label"},"Email address"),a.createElement("input",{id:"nl-sw-email",type:"email",name:"email",placeholder:"[email protected]",required:!0,autoComplete:"email",className:"nl-sw-input",disabled:"loading"===t}),"err"===t&&a.createElement("p",{className:"nl-sw-error",role:"alert"},l),a.createElement("button",{type:"submit",className:"nl-sw-btn",disabled:"loading"===t},"loading"===t?"Connecting…":"Subscribe to intel →"),a.createElement("p",{className:"nl-sw-legal"},"No spam. No vendor fluff. Unsubscribe any time."))))}},8963:function(e,t,n){n.d(t,{A:function(){return l}});var a=n(6540);function l({title:e,subtitle:t,primaryLink:n,primaryText:l,secondaryLink:r,secondaryText:i,backgroundImage:o}){const s=o?{backgroundImage:`linear-gradient(135deg, rgba(37, 99, 235, 0.85) 0%, rgba(13, 33, 55, 0.9) 100%), url(${o})`,backgroundSize:"cover",backgroundPosition:"center"}:{};return a.createElement("section",{className:"hero blueprint-section-subtle",style:s},a.createElement("div",{className:"container"},a.createElement("h1",null,e),t&&a.createElement("p",null,t),(n||r)&&a.createElement("div",{style:{display:"flex",gap:"var(--space-md)",flexWrap:"wrap"}},n&&a.createElement("a",{href:n,className:"btn btn-primary"},l||"Get Started"),r&&a.createElement("a",{href:r,className:"btn btn-outline"},i||"Learn More"))))}}}]);
2//# sourceMappingURL=component---src-components-page-template-jsx-content-file-path-content-posts-powershell-payloads-mdx-6bb3642f994aa89b3fe8.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.