SaSkiller wrote: » I was told that blocking powershell can wreck modern windows OS' due to some kind of weird integration with the OS, it uses PS even when someone isn't using it directly?
636-555-3226 wrote: » Uninstall it. As part of my build process we use it to deploy images/software and one of the last steps is uninstalling it. Most workstations & servers have no need of it. Yes, PS can be very useful, but it can also be very destructive in the right hands (I'm looking at you PowerShellMafia, PowerShellEmpire, et al). If you have the infrastructure, you might also be able to set up your IPS to detect & kill & alert any PS traffic it sees unless it's coming from the 3 or 4 admin boxes you've previously identified as being OK to use PS. If you've got a PS alert coming from a workstation that shouldn't have anything to do with PS, time to parking lot that switchport and vlan yourself over to sneaknet to see what's up.