Microsoft documents System.Net.WebClient.DownloadFile as a .NET method for retrieving files from a remote resource, while Splunk Threat Research highlights the same capability as a common indicator of malicious PowerShell activity when used from endpoint processes. The behavior is frequently associated with attackers and offensive frameworks downloading follow-on payloads that can lead to unauthorized code execution, data exfiltration, or wider compromise.
Splunk said its older analytic, Any Powershell DownloadFile, was removed from the content library and replaced by Windows File Download Via PowerShell with updated logic and grouping. The detection monitors process-execution telemetry from sources including Sysmon Event ID 1, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2, maps to MITRE ATT&CK techniques T1059.001 and T1105, and may require tuning to reduce false positives based on parent process or command-line context.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk marked the "Any Powershell DownloadFile" analytic as removed from its content library and stated it is no longer maintained or supported. Splunk said it was replaced by a newer detection, "Windows File Download Via PowerShell," with improved logic and grouping, and listed the removal in version 5.12.0.
Splunk Threat Research published a TTP detection named "Any Powershell DownloadFile" to identify PowerShell use of the DownloadFile method via endpoint process execution telemetry. The detection was authored by Michael Haag and associated with Splunk Enterprise Security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.