May 20, 2022


Using DLLs or a standalone executable, unmanaged PowerShell execution is possible.

  1. Use rundll32.exe, installutil.exe, regsvcs.exe or regasm.exe, regsvr32.exe to run Powershell with DLLs.
  2. Run Powershell without using the powershell.exe or powershell ise.exe executables.
  3. Features of the AMSI Bypass.
  4. Execute Powershell scripts or Powershell files straight from the command line.
  5. Use Powershell Cmdlets and import Powershell modules.

Disclaimer: : The intended use for the tool is strictly educational and should not be used for any other purposes.

