Netskope Threat Labs

PWSH.Agent

ATP Sandbox Adv. HeuristicsAV

This generic detection identifies malicious PowerShell scripts that perform unauthorized actions on infected systems, without attributing them to a specific family.

First seen
September 2022
Last seen
October 2026
Alert Name
Backdoor.PWSH.Agent.B
Dropped:Trojan.PWSH.Agent.BZ
Dropped:Trojan.PWSH.Agent.CL
Dropped:Trojan.PWSH.Agent.CM
Generic.PWSH.Agent.A.1E606799
Generic.PWSH.Agent.A.26DE5F56
Generic.PWSH.Agent.A.644EF254
Generic.PWSH.Agent.A.73ABBEA7
Generic.PWSH.Agent.A.84A861AC
Generic.PWSH.Agent.A.959FBF00