<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>PowerShell on Security Adventures</title><link>https://www.craigcarr.io/tags/powershell/</link><description>Recent content in PowerShell on Security Adventures</description><generator>Hugo</generator><language>en-GB</language><copyright/><lastBuildDate>Fri, 04 Sep 2026 01:12:29 +0100</lastBuildDate><atom:link href="https://www.craigcarr.io/tags/powershell/index.xml" rel="self" type="application/rss+xml"/><item><title>Dissecting a multi-stage PowerShell malware loader</title><link>https://www.craigcarr.io/posts/dissecting-a-multistage-powershell-malware-loader/</link><pubDate>Fri, 04 Sep 2026 01:12:29 +0100</pubDate><guid>https://www.craigcarr.io/posts/dissecting-a-multistage-powershell-malware-loader/</guid><description><![CDATA[<p><picture><img class="img-fluid " alt="SIEM incident overview showing a multi-stage execution and defence-evasion alert" src="/posts/dissecting-a-multistage-powershell-malware-loader/incident-overview.png" loading="lazy" width="1021" height="131" />
</picture>

</p>
<p>An interesting malware event landed in our SIEM. It was caught when it tried to load a .NET module. Right from the start, something told me that this was malicious but also interesting enough to warrant further investigation. A quick foreword: the GitHub account serving this was reported. At the time of writing, only the <code>impromptu</code> file has been taken down; the rest of the account continues to host malicious-looking scripts.</p>]]></description></item></channel></rss>