Emulating T1059.001 until the detection actually fires

Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.

The rule looked reasonable. It matched encoded PowerShell commands, it had been running for a month, and it had never produced a false positive. That last part should have been the tell.

This is the afternoon spent proving it only caught the version of the technique I happened to have in mind when I wrote it.

[!] members only

The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included