Skip to content

Glossary

Invoke-Expression (IEX)

A PowerShell cmdlet that runs a string as code — the execution half of most download cradles and obfuscation chains.

Invoke-Expression (alias IEX) evaluates a string as a PowerShell command. It is the execution step that turns a decoded or downloaded string into running code, so it appears at the end of most download cradles and obfuscation chains (IEX $decoded, & ([scriptblock]::Create($s))).

Legitimate uses exist but are rare in day-to-day administration, so IEX applied to a downloaded or decoded string is a strong triage signal. This parser flags Invoke-Expression and [scriptblock]::Create and, when paired with a download, raises it to a download-cradle finding. See decoding encoded commands.