Skip to content

Glossary

PowerShell downgrade attack

Launching PowerShell version 2 to escape the script block logging and AMSI that only exist in version 5.

A downgrade attack runs powershell.exe -Version 2 so the session uses the PowerShell 2.0 engine, which has no script block logging, no module logging and no AMSI. If the .NET 2.0/3.5 runtime and the v2 engine are present, an attacker gains a scripting environment that leaves far less evidence.

The tell-tale sign is a -Version 2 (or -v 2) on a PowerShell command line, visible in the classic log's HostApplication and EngineVersion fields, which this parser flags. See Lee Holmes on downgrade attacks.