Identifying Fileless Malware via PowerShell Execution
A security analyst is reviewing an IDS alert and sees the following: C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe -noP -exe byPass -nonI -wind hidden -no1 -c dir;findstr /s maldinuv %USERPROFILE%\\*.lnk > %USERPROFILE%\Documents\iijlqe.ps1;%USERPROFILE%\Documents\iijlqe.psi;exit Which of the following triggered the IDS alert?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to recognize PowerShell abuse patterns (bypassing restrictions) as indicators of fileless malware rather than traditional network or application attacks.
This question analyzes a PowerShell command line containing execution bypass flags to determine the specific attack type. The correct identification is fileless malware execution, leveraging legitimate system tools for malicious purposes.
Learners often miss the significance of 'ExecutionPolicy Bypass' and focus on the directory listing aspect, potentially misidentifying it as simple reconnaissance or a different type of malware.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The command line explicitly usespowershell.exe with critical arguments like -exe byPass (ExecutionPolicy Bypass) and -wind hidden (WindowStyle Hidden). These are hallmarks of fileless malware, which executes code directly in memory using trusted system utilities like PowerShell to evade signature-based detection. The script attempts to search for specific files and redirect output, operating without dropping a traditional executable payload on disk.Why the Other Options Are Wrong
Bluesnarfing (A) targets Bluetooth vulnerabilities, which is unrelated to Windows PowerShell. URL redirection (B) involves web traffic manipulation, not local command-line execution. Macro-based denial of service (D) typically refers to Office automation scripts causing crashes, whereas this command is performing active reconnaissance and persistence mechanisms typical of advanced persistent threats (APTs).Community Comment Notes
Community consensus strongly supports C. As user Hs1208 noted, "Fileless malware often uses legitimate system tools, such as PowerShell, to run malicious code directly in memory." User LayinCable correctly eliminated other options by pointing out the absence of Bluetooth or URLs. User glenndexter analyzed the specific commands (dir, findstr) as part of the malicious workflow. Official Reference
Exam Strategy
When you see PowerShell commands with flags like -NonInteractive, -NoProfile, or -ExecutionPolicy Bypass, immediately consider fileless malware. Memorize these common evasion techniques to quickly identify them in exam scenarios.
Frequently Asked Questions
Why is this not a macro-based DoS?
Macros are associated with Office documents (VBA). This is a direct PowerShell CLI invocation, characteristic of fileless malware, not a document macro crash.
What does -exe byPass do?
It sets the ExecutionPolicy to 'Bypass', allowing scripts to run without warnings or prompts, a key tactic for fileless attacks to avoid triggering security alerts.