PowerSploit
MITRE ATT&CK: S0194 View on attack.mitre.org
Aliases: PowerSploit
- First seen
- 2012-07-01 00:00:00
- Malware type
- exploit-kit
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-18 22:33:28
- Profile updated
- 2026-07-07 15:32:56
Context
PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration.
Detection coverage
- 608 Sigma rules
Malware & tools used
- Path Interception by PATH Environment Variable (attack-pattern)
- Keylogging (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Credentials in Registry (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- Audio Capture (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Path Interception by Unquoted Path (attack-pattern)
- Query Registry (attack-pattern)
- Data from Local System (attack-pattern)
- Group Policy Preferences (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Command Obfuscation (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Windows Service (attack-pattern)
- Screen Capture (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Scheduled Task (attack-pattern)
- DLL (attack-pattern)
- Path Interception by Search Order Hijacking (attack-pattern)
- Kerberoasting (attack-pattern)
- Local Account (attack-pattern)
- Security Support Provider (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Credential Manager (attack-pattern)
Used by threat actors
- Operation Wocao (campaign)
- CostaRicto (campaign)
- Earth Lusca (threat-actor)
- TA505 (threat-actor)
- Patchwork (threat-actor)
- APT41 (threat-actor)
- APT33 (threat-actor)
- menuPass (threat-actor)
- FIN7 (threat-actor)
- Leviathan (threat-actor)
- MuddyWater (threat-actor)
Reports & references
- powersploit.readthedocs.io (report)
- powershellmagazine.com — Powersploit (report)
- MITRE ATT&CK — S0194 (report)
- github.com — Powersploit (report)