{
  "node_id": "mitre-attack-t1059-001-powershell",
  "title": "MITRE ATT&CK T1059.001: PowerShell (Sub-Technique of T1059 - Execution)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-12",
  "bluf": "MITRE ATT&CK T1059.001 covers adversary abuse of PowerShell for execution, lateral movement, and discovery. PowerShell is the dominant living-off-the-land interpreter on Windows: every modern ransomware operator (LockBit, BlackCat, Cl0p, Akira, Royal) uses PowerShell for at least one stage. Empire, PoshC2, Nishang, PowerSploit, and Cobalt Strike provide weaponised PowerShell payloads. Compliance obligations include NIST SP 800-53 SI-7 (Software Integrity), CM-7 (Least Functionality), SI-3 (Malicious Code Protection), AU-2 (Event Logging), ISO 27001 A.8.19, A.8.16, PCI DSS Req 10.4, and CIS Microsoft Windows Server Benchmark.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "mitre-attack-t1059-command-and-scripting-interpreter",
    "mitre-attack-t1204-user-execution",
    "mitre-attack-t1106-native-api",
    "nist-sp-800-53-r5",
    "iso-27001-2022"
  ],
  "primary_citations_count": 8
}