NSA warns against silly mistake in the fight against Windows malware

PowerShell can be used for good, too

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

Task automation platform PowerShell, which is often abused by threat actors distributingmalware, can also be used for attack detection and prevention. This is the advice the US National Security Agency (NSA) recently gave to system administrators everywhere.

Alongside cybersecurity centers in the UK and New Zealand, the NSA published a security advisory in which it argues that blocking PowerShell, a common security practice, actually lowers organizations’ defensive capabilities againstransomwareand other forms of cyberattacks.

Instead, system admins should use it to boost their forensics and incident response, as well as to automate as many repetitive tasks as possible.

Share your thoughts on Cybersecurity and get a free copy of the Hacker’s Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at theend of this surveyto get the bookazine, worth $10.99/£10.99.

Numerous recommendations

Numerous recommendations

“Blocking PowerShell hinders defensive capabilities that current versions of PowerShell can provide, and prevents components of the Windowsoperating systemfrom running properly. Recent versions of PowerShell with improved capabilities and options can assist defenders in countering abuse of PowerShell,” the NSA stated.

The advisory comes with a number of recommendations, including leveraging PowerShell remoting, or using Secure Shell protocol (SSH) to improve the security of public-key authentication.

“Proper configuration of WDAC or AppLocker onWindows 10+ helps to prevent a malicious actor from gaining full control over a PowerShell session and the host,” the document explained.

System admins can also hunt for signs of abuse on theirendpointsby recording PowerShell activity and monitoring logs.

Are you a pro? Subscribe to our newsletter

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Patch PowerShell now, Microsoft tells admins>Microsoft warns users to update PowerShell ‘as soon as possible’>Hackers have found a sneaky new way to infect Windows devices

The advisory also recommends admins turn on features such as Deep Script Block Logging, Module Logging, or Over-The-Shoulder Transcription, as the former create a logdatabase, handy for spotting aggressive PowerShell activity.

The latter allows admins to record every PowerShell input and output, getting a better understanding of the attackers’ goals.

“PowerShell is essential to secure the Windows operating system,” the NSA concluded, adding that, with proper configuration and management, it can be a great tool for system maintenance and security.

ViaBleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

This new phishing strategy utilizes GitHub comments to distribute malware

Should your VPN always be on?

NYT Strands today — hints, answers and spangram for Sunday, November 10 (game #252)