BIOC Informational

PowerShell is used to execute a CPL file

Attackers may use PowerShell.exe to execute a CPL file to achieve Control Panel proxy execution.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Control Panel (T1218.002)
Indicator:

Process action type = execution AND target process name = powershell.exe , powershell_ise.exe , pwsh.exe AND target process cmd = * control.exe *.cpl*

Preventable: yes