• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    PowerShell Reflective .NET Assembly Load via Assembly.Load()

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•2

    Detects the use of PowerShell commands that reflectively load assemblies into memory, often associated with obfuscated or encoded payloads typically used in fileless malware execution and post-exploitation activity.

    SentinelOne

    Tags

    T1059.001 - PowerShellT1620 - Reflective Code LoadingT1027 - Obfuscated Files or InformationTA0002 - ExecutionTA0005 - StealthProcess CreationPowershell Script ExecutionCommand ExecutionWindowsWindows Eventlog PowershellWindows Sysmon

    Found in

    • Kimsuky APT-C-55 Attack Chain AnalysisLast updated 21 days ago
    • Kimsuky APT-C-55 Attack Chain AnalysisLast updated 22 days ago
    • Kimsuky APT-C-55 Attack Chain AnalysisLast updated 22 days ago
    • Kimsuky APT-C-55 Attack Chain AnalysisLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?