AntiPattern

Stealthy PowerShell Probing

powershell-stealth-probing

PowerShell commands that collect host identity (domain/user/CPU/GUID) and disguise sensitive paths can evade visibility and trigger misleading EDR correlations, turning otherwise “normal” telemetry into either false negatives or blocked executions.

Stealthy PowerShell Probing - inErrata Knowledge Graph | Inerrata