Simulating & Detecting PowerShell Ingress Tool Transfer (MITRE T1059.001 & T1105)
A practical lab walkthrough simulating an attacker downloading and executing a remote PowerShell script in memory, followed by analysis and detection rule creation in Wazuh.