Title:Suspicious PowerShell WindowStyle Option Status:test Description:Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
In some cases, windows that would typically be displayed when an application carries out an operation can be hidden
References: -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1564.003/T1564.003.md Author: frack113, Tim Shelton (fp AWS) Date: 2021-10-20 modified:2023-01-03 Tags:
-'attack.stealth'
-'attack.t1564.003'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled