Netskope Threat Labs

PowerSploit

ATP Sandbox Adv. HeuristicsAVNetskope IPS

PowerSploit is a PowerShell post exploitation framework whose modules automate reconnaissance, code execution, persistence, and data exfiltration on Windows systems. Its scripts run through the PowerShell interpreter, which blurs into normal administrative activity, and its library became a foundation for later offensive toolkits. Cyberattackers use it heavily in intrusions, so defenders monitor for its distinctive script patterns and constrain PowerShell wherever possible.

First seen
January 2022
Last seen
October 2026

28 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0009 Collection

Alert Name
Application.HackTool.PowerSploit.A
Application.HackTool.PowerSploit.B
Application.HackTool.PowerSploit.C
Application.HackTool.PowerSploit.D
Application.HackTool.PowerSploit.E
Application.HackTool.PowerSploit.F
Application.HackTool.PowerSploit.G
Application.HackTool.PowerSploit.H
Application.HackTool.PowerSploit.I
Application.HackTool.PowerSploit.J