POWERPOST

Description

(Mandiant) POWERPOST is a reconnaissance tool written in PowerShell that can collect data on a local host including system information and user account names. POWERPOST writes the data to disk and then sends the collected data to a hardcoded remote server via HTTP POSTs.

Names

Name
POWERPOST

Category

Malware

Type

  • Reconnaissance
  • Info stealer

Information

Other Information

Uuid

db08b971-ae57-4551-a6d2-94fe410af149

Last Card Change

2022-09-13