Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1059.001: PowerShell (Sub-Technique of T1059 - Execution)

MITRE ATT&CK T1059.001 covers adversary abuse of PowerShell for execution, lateral movement, and discovery. PowerShell is the dominant living-off-the-land…

What MITRE ATT&CK T1059.001: PowerShell (Sub-Technique of T1059 - Execution) requires

MITRE ATT&CK T1059.001 covers adversary abuse of PowerShell for execution, lateral movement, and discovery. PowerShell is the dominant living-off-the-land interpreter on Windows: every modern ransomware operator (LockBit, BlackCat, Cl0p, Akira, Royal) uses PowerShell for at least one stage. Empire, PoshC2, Nishang, PowerSploit, and Cobalt Strike provide weaponised PowerShell payloads. Compliance obligations include NIST SP 800-53 SI-7 (Software Integrity), CM-7 (Least Functionality), SI-3 (Malicious Code Protection), AU-2 (Event Logging), ISO 27001 A.8.19, A.8.16, PCI DSS Req 10.4, and CIS Microsoft Windows Server Benchmark.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1059/001/

SHA-256 integrity: 0700bb98051ce56f586289288dcb2035865ec14fa6cec8af744e389de6caecaa

Primary Citations — 8 traced to source

  • MITRE ATT&CK Technique T1059.001: PowerShell (https://attack.mitre.org/techniques/T1059/001/)
  • NIST SP 800-53 Rev 5: SI-7 (Software Integrity), CM-7 (Least Functionality)

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.