CompTIA CySA+ (CS0-003)Security OperationsMedium

An analyst reviewing endpoint logs finds the following PowerShell command executed by a non-administrative user: powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAn... Which characteristic of this command is the STRONGEST indicator of malicious intent?

  1. AThe Base64-encoded command combined with hidden window and download activity
  2. BThe .exe file extension present in the process name
  3. CThe command was run by a non-administrative user account
  4. DThe use of the -NoP (NoProfile) flag to speed up execution
Show answer & explanation

Correct answer: A. The Base64-encoded command combined with hidden window and download activity

Base64-encoded PowerShell (-Enc) combined with a hidden window (-W Hidden) is a common obfuscation and living-off-the-land technique used to conceal a downloader/execution payload, strongly indicating malicious intent versus benign scripting.

Why the other options are wrong

  • B. powershell.exe naturally has a .exe extension; this is expected and not an indicator.
  • C. Non-admin execution alone isn't inherently suspicious since PowerShell is available to standard users.
  • D. -NoProfile is a benign, commonly used flag for faster script execution, not inherently malicious.

PowerShell Obfuscation Indicator

Malicious PowerShell often combines Base64-encoded commands (-EncodedCommand), hidden windows, and network download cradles to evade detection while retrieving/executing payloads.

  • -Enc/-EncodedCommand obscures the actual command from casual view
  • -W Hidden suppresses the console window from the user
  • Net.WebClient.DownloadString is a common fileless download technique

Memory trick: Encoded + Hidden + Download = a masked burglar sneaking in through a hidden window.

More Security Operations questions