PowerSploit is an open-source PowerShell post-exploitation framework for Windows, originally developed for penetration testing and frequently repurposed in intrusion activity. Its modules support host and Active Directory reconnaissance, credential discovery from Windows Registry locations and configuration artifacts, keystroke logging, periodic screen capture, local data collection, persistence through scheduled tasks and Registry Run keys, privilege enumeration, and code execution. The framework includes PowerUp components for identifying and exploiting local privilege-escalation opportunities, including DLL search-order hijacking conditions. Its reflective loading components can execute Windows PE files in memory and inject DLLs or shellcode into local or remote processes, reducing on-disk artifacts. PowerSploit has been used by threat actors including Conti operators, WastedLocker-associated actors, PurpleFox operators, and in malware delivery chains such as ChChes. It targets Windows systems and requires PowerShell execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PowerSploit modules are written in and executed via PowerShell.
PowerSploit modules are written in and executed via PowerShell.
PowerSploit modules are written in and executed via PowerShell.
Since the emergence of MuddyWater, we found that its operators used multiple open source post-exploitation tools... PowerSploit
The keb.ps1 script belongs to the popular PowerSploit framework for penetration testing and kicks off a Kerberoasting attack.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The article demonstrates destructive scripts executed through PowerShell, including `loadram.ps1`, `loadcpu.ps1`, `license.ps1`, `killer.ps1`, and PowerSploit Mayhem functions.
$Win32Functions.VirtualAllocEx.Invoke($RemoteProcHandle...); $Win32Functions.WriteProcessMemory.Invoke(...); Create-RemoteThread -ProcessHandle $RemoteProcHandle -StartAddress $VoidFuncAddr | $VirtualAllocAddr = Get-ProcAddress kernel32.dll VirtualAlloc ... $CreateRemoteThreadAddr = Get-ProcAddress kernel32.dll CreateRemoteThread
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
This is probably most useful for injecting backdoors in SYSTEM processes in Session0.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
2.) Reflectively load a DLL in to memory of a remote process. As mentioned above, the DLL being reflectively loaded won't be displayed when tools are used to list DLLs of the running remote process. | Reflectively load a DLL in to memory of a remote process... This is probably most useful for injecting backdoors in SYSTEM processes in Session0.
Refectively load DemoDLL_RemoteProcess.dll in to the lsass process on a remote computer.
The script starts by checking the Windows version and applied hotfixes for the vulnerabilities it is targeting... After selecting the appropriate vulnerability, it uses the PowerSploit module to reflectively load the embedded exploit bundle binary with the target vulnerability and an MSI command as arguments.
This is probably most useful for injecting backdoors in SYSTEM processes in Session0.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
2.) Reflectively load a DLL in to memory of a remote process. As mentioned above, the DLL being reflectively loaded won't be displayed when tools are used to list DLLs of the running remote process. | Reflectively load a DLL in to memory of a remote process... This is probably most useful for injecting backdoors in SYSTEM processes in Session0.
Refectively load DemoDLL_RemoteProcess.dll in to the lsass process on a remote computer.
Remove 'MZ' from the PE file so that it cannot be detected by .imgscan in WinDbg
This tool can be run on remote servers by supplying a local Windows PE file (DLL/EXE) to load in to memory on the remote system, this will load and execute the DLL/EXE in to memory without writing any files to disk.
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
Nearly all tools leveraged are being used in their PowerShell versions, including Mimikatz and PowerSploit.
OS Credential Dumping: LSASS Memory T1003.001 Basic description The subtechnique known as OS Credential Dumping: LSASS Memory T1003.001 is used by attackers to obtain credentials in a Windows OS.
Technical details | Credential Access TA0006 | OS Credential Dumping: NTDS T1003.003 ... Another popular way to dump ntds.dit is to use the ntdsutil.exe utility.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
Le mode opératoire scanne le réseau pour collecter plus d’informations sur le SI et découvrir des services vulnérables.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The resource-exhaustion scripts can be used "as a DoS tactic to slow down a server"; Set-CriticalProcess causes a process termination to "immediately force[] a system crash."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
82 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based post-exploitation framework referenced as commonly using memory manipulation techniques such as reflective PE injection and shellcode execution.
A PowerShell-based offensive framework mentioned in the context of memory manipulation, reflective PE injection, and shellcode execution techniques.
A PowerShell-based post-exploitation framework that can be downloaded and executed via malicious PowerShell commands.
PowerShell-based post-exploitation framework mentioned only as the name of a built-in detection alert; no use in this intrusion is described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.