home.social

#powershell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #powershell, aggregated by home.social.

  1. Windows w praktyce: szukanie sekretów w systemie z użyciem PowerShell

    Wstęp Rok 2026 przyzwyczaił nas do tego, że zagrożeniem bywa nie tylko złośliwe oprogramowanie tworzone przez atakujących, ale i narzędzia, którym ufamy na co dzień. Naruszenia łańcucha dostaw w kolejnych produktach, o których regularnie czytamy w mediach branżowych, pokazują, że skrypt czy pakiet o ugruntowanej renomie potrafi z dnia na...

    #Aktualności #Narzędzia #Activedirectory #Hasła #Linpeas #Powershell #Redteam #Sekrety #Windows #Winpeas

    sekurak.pl/windows-w-praktyce-

  2. Windows w praktyce: szukanie sekretów w systemie z użyciem PowerShell

    Wstęp Rok 2026 przyzwyczaił nas do tego, że zagrożeniem bywa nie tylko złośliwe oprogramowanie tworzone przez atakujących, ale i narzędzia, którym ufamy na co dzień. Naruszenia łańcucha dostaw w kolejnych produktach, o których regularnie czytamy w mediach branżowych, pokazują, że skrypt czy pakiet o ugruntowanej renomie potrafi z dnia na...

    #Aktualności #Narzędzia #Activedirectory #Hasła #Linpeas #Powershell #Redteam #Sekrety #Windows #Winpeas

    sekurak.pl/windows-w-praktyce-

  3. Windows w praktyce: szukanie sekretów w systemie z użyciem PowerShell

    Wstęp Rok 2026 przyzwyczaił nas do tego, że zagrożeniem bywa nie tylko złośliwe oprogramowanie tworzone przez atakujących, ale i narzędzia, którym ufamy na co dzień. Naruszenia łańcucha dostaw w kolejnych produktach, o których regularnie czytamy w mediach branżowych, pokazują, że skrypt czy pakiet o ugruntowanej renomie potrafi z dnia na...

    #Aktualności #Narzędzia #Activedirectory #Hasła #Linpeas #Powershell #Redteam #Sekrety #Windows #Winpeas

    sekurak.pl/windows-w-praktyce-

  4. Windows w praktyce: szukanie sekretów w systemie z użyciem PowerShell

    Wstęp Rok 2026 przyzwyczaił nas do tego, że zagrożeniem bywa nie tylko złośliwe oprogramowanie tworzone przez atakujących, ale i narzędzia, którym ufamy na co dzień. Naruszenia łańcucha dostaw w kolejnych produktach, o których regularnie czytamy w mediach branżowych, pokazują, że skrypt czy pakiet o ugruntowanej renomie potrafi z dnia na...

    #Aktualności #Narzędzia #Activedirectory #Hasła #Linpeas #Powershell #Redteam #Sekrety #Windows #Winpeas

    sekurak.pl/windows-w-praktyce-

  5. Windows w praktyce: szukanie sekretów w systemie z użyciem PowerShell

    Wstęp Rok 2026 przyzwyczaił nas do tego, że zagrożeniem bywa nie tylko złośliwe oprogramowanie tworzone przez atakujących, ale i narzędzia, którym ufamy na co dzień. Naruszenia łańcucha dostaw w kolejnych produktach, o których regularnie czytamy w mediach branżowych, pokazują, że skrypt czy pakiet o ugruntowanej renomie potrafi z dnia na...

    #Aktualności #Narzędzia #Activedirectory #Hasła #Linpeas #Powershell #Redteam #Sekrety #Windows #Winpeas

    sekurak.pl/windows-w-praktyce-

  6. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  7. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  8. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  9. PowerShell Weekly for September 11, 2026 has just dropped! Explore cutting-edge techniques and community news in this week's edition. Read it now and stay ahead of the curve!
    #PowerShell #Automation #TechNews
    psweekly.dowst.dev/?p=9229

  10. Are you validating your #PowerShell code before CI?

    At #PSConfEU, Martin Howlett shows how to:
    ✅ Run validation locally
    ✅ Use Invoke-Build validate everywhere
    ✅ Align dev, CI & #AI workflows

    Same checks, everywhere.

    👉 youtu.be/ER99PSiNUG0?si=Ut2...

    #automation #IT #DevOps #Conference

    - YouTube

  11. Are you validating your #PowerShell code before CI?

    At #PSConfEU, Martin Howlett shows how to:
    ✅ Run validation locally
    ✅ Use Invoke-Build validate everywhere
    ✅ Align dev, CI & #AI workflows

    Same checks, everywhere.

    👉 youtu.be/ER99PSiNUG0?si=Ut2...

    #automation #IT #DevOps #Conference

    - YouTube

  12. Technology moves fast. Sharing knowledge never goes out of style.

    The Call for Papers for #PSConfEU #MiniCon 2026 is open until 25 September.

    👉 sessionize.com/psconfeu-min...

    #PowerShell #Conference #IT #automation #Europe #retro

  13. SloppyRAT: A New Tool For Ransomware Attacks

    In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

    Pulse ID: 6aa2ea5fc313035064df8d21
    Pulse Link: otx.alienvault.com/pulse/6aa2e
    Pulse Author: AlienVault
    Created: 2026-09-10 17:35:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EtherHiding #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #RPC #RansomWare #SMS #TLS #bot #AlienVault

  14. SloppyRAT: A New Tool For Ransomware Attacks

    In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

    Pulse ID: 6aa2ea5fc313035064df8d21
    Pulse Link: otx.alienvault.com/pulse/6aa2e
    Pulse Author: AlienVault
    Created: 2026-09-10 17:35:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EtherHiding #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #RPC #RansomWare #SMS #TLS #bot #AlienVault

  15. SloppyRAT: A New Tool For Ransomware Attacks

    In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

    Pulse ID: 6aa2ea5fc313035064df8d21
    Pulse Link: otx.alienvault.com/pulse/6aa2e
    Pulse Author: AlienVault
    Created: 2026-09-10 17:35:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EtherHiding #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #RPC #RansomWare #SMS #TLS #bot #AlienVault

  16. SloppyRAT: A New Tool For Ransomware Attacks

    In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

    Pulse ID: 6aa2ea5fc313035064df8d21
    Pulse Link: otx.alienvault.com/pulse/6aa2e
    Pulse Author: AlienVault
    Created: 2026-09-10 17:35:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EtherHiding #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #RPC #RansomWare #SMS #TLS #bot #AlienVault

  17. SloppyRAT: A New Tool For Ransomware Attacks

    In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

    Pulse ID: 6aa2ea5fc313035064df8d21
    Pulse Link: otx.alienvault.com/pulse/6aa2e
    Pulse Author: AlienVault
    Created: 2026-09-10 17:35:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EtherHiding #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #RPC #RansomWare #SMS #TLS #bot #AlienVault

  18. Everyone online who says they've never had issues with #Windows is either inexperienced or just blatantly lying.

    Again one of those days when all of a sudden OBS cannot record audio.

    Had to jump through a lot of hoops of troubleshooting and switching audio devices didn't do jack shit.

    OBS was greyed out in the audio mixer. That ultimately let me to the solution.

    Had to run this with admin privileges in #PowerShell to fix it:

    Restart-Service -Name AudioEndpointBuilder, Audiosrv -Force

  19. Открыл обычный VBS, а внутри оказался PowerShell, AES и MSBuild

    Мне в руки попался обычный файл с расширением .vbs . Ничего необычного. Открываю посмотреть, что там внутри, и сначала даже немного разочаровался. Какой-то VBScript, временные файлы, cmd.exe , PowerShell. Ну, думаю, очередной скрипт-загрузчик. Но потом заметил одну деталь. Скрипт читал сам себя. И вот тут стало уже интереснее.

    habr.com/ru/articles/1080644/

    #реверсинжиниринг #информационная_безопасность #vbs #powershell #вредонос #malware

  20. Using Powershell in Windows? There are delicious dessert alternatives to Homebrew 🍻🍺🍨🍧🍦

    Alternative package managers below! 🍡🍪
    scoop.sh
    chocolatey.org

    #Python #powershell

  21. Using Powershell in Windows? There are delicious dessert alternatives to Homebrew 🍻🍺🍨🍧🍦

    Alternative package managers below! 🍡🍪
    scoop.sh
    chocolatey.org

  22. 👋 21-24 June 2027 👋
     
    That's the only thing we're announcing today.

    If you'd like to hear about ticket sales, speaker announcements and other #PSConfEU updates before everyone else, subscribe on our website psconf.eu

    #PowerShell #Automation #IT #Conference

  23. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  24. Claude Code в Telegram голосом: свой мост, когда официальный канал выключен

    MCP-сервер отвечает Connected. Инструменты работают: бот сам присылает мне сообщения. Мои сообщения до бота доходят, я вижу их в очереди Telegram. А в сессию Claude Code они не попадают. Ни ошибки, ни предупреждения. Полтора часа я искал не там. Меня зовут Сол ГудКод, и обычно я вытаскиваю людей из ситуаций, в которые они сами себя загнали, но на этот раз клиентом оказался я сам: мне нужен был бот, которому можно наговорить задачу голосом из дороги, чтобы он сделал её на моей машине и в моих проектах. У Anthropic такое есть официально, и именно поэтому история вышла длиннее, чем я рассчитывал. Внутри: как отличить эту тишину от своей ошибки за минуту и чем я заменил официальный канал. Плюс восемь мест, где я наступил на грабли Windows. В том числе на те, куда уже наступал в этом же проекте. И на ту, где Claude вежливо попросил меня договорить мысль.

    habr.com/ru/articles/1063578/

    #claude_code #телеграмбот #anthropic #ииагенты #llm #whisper #fasterwhisper #powershell #голосовое_управление #mcp

  25. Управляющие последовательности (ANSI)

    Что такое ANSI коды и как их обрабатывает терминал? Зачем нужны эмуляторы терминала? Как отформатировать вывод в PowerShell из AutoHotkey? Разбираемся в этой статье.

    habr.com/ru/articles/1054876/

    #powershell #autohotkey #ansi #escaped_sequence #control_sequence #vt100 #output #console #terminal #history