{"id":47223,"date":"2022-06-23T10:14:43","date_gmt":"2022-06-23T10:14:43","guid":{"rendered":"http:\/\/d02e3953-7fe7-4115-9ab6-0ea746ef0563"},"modified":"2022-06-23T10:14:43","modified_gmt":"2022-06-23T10:14:43","slug":"nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","title":{"rendered":"NSA, CISA say: Don&#8217;t block PowerShell, here&#8217;s what to do instead"},"content":{"rendered":"<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage\"><!----> <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/\" alt=\"Worried businessman looking at computer screen at his workplace in office\" height=\"800\" width=\"1200\"><\/picture><\/div>\n<p> <!----> <!----><\/div>\n<p> <!----><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall g-color-gray70 u-block g-text-xsmall\">Image: Getty Images\/iStockphoto<\/span><\/figcaption><\/figure>\n<p>Cybersecurity authorities from the US, the UK, and <a href=\"https:\/\/www.ncsc.govt.nz\/newsroom\/csi-keeping-powershell\/\" target=\"_blank\" rel=\"noopener\">New Zealand<\/a> have advised businesses and government agencies to properly configure Microsoft&#8217;s built-in Windows command-line tool, PowerShell \u2013 but not to remove it.&nbsp; &nbsp;&nbsp;<\/p>\n<p>Defenders shouldn&#8217;t disable PowerShell, a scripting language, because it is a useful command-line interface for Windows that can help with forensics, incident response and <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-this-windows-10-powershell-script-lets-you-securely-fight-coronavirus-with-foldinghome\/\" rel=\"follow\">automating desktop tasks<\/a>,&nbsp;<a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/06\/22\/keeping-powershell-measures-use-and-embrace\" target=\"_blank\" rel=\"noopener\">according to joint advice<\/a>&nbsp;from the US spy service the National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), and the New Zealand and UK national cybersecurity centres.&nbsp;<\/p>\n<p>It also lets admins automate security tasks on Microsoft&#8217;s Azure cloud platform. Users can, for example, write PowerShell commands to manage Microsoft&#8217;s Defender antivirus on Windows 10 and Windows 11.<\/p>\n<p><strong>SEE:&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/cloud-computing-dominates-but-security-is-now-its-biggest-challenge\/#link=%7B%22role%22:%22standard%22,%22href%22:%22https:\/\/www.zdnet.com\/article\/cloud-computing-dominates-but-security-is-now-its-biggest-challenge\/%22,%22target%22:%22_blank%22,%22absolute%22:%22%22,%22linkText%22:%22%3Cstrong%3ECloud%20computing%20dominates.%20But%20security%20is%20now%20the%20biggest%20challenge%3C\/strong%3E%22%7D\" rel=\"follow\">Cloud computing dominates. But security is now the biggest challenge<\/a><\/strong><\/p>\n<p>But PowerShell&#8217;s flexibility has also <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-this-unusual-windows-and-linux-malware-does-everything-it-can-to-stay-on-your-network\/\" rel=\"follow\">made it amenable<\/a> to attackers <a href=\"https:\/\/www.zdnet.com\/article\/turla-turns-powershell-into-a-weapon-in-attacks-against-eu-diplomats\/\" rel=\"follow\">who&#8217;ve used it<\/a> to <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-this-unusual-windows-and-linux-malware-does-everything-it-can-to-stay-on-your-network\/\" rel=\"follow\">remotely compromise Windows devices<\/a> and even Linux systems.&nbsp;<\/p>\n<p>So, what should defenders do? Remove PowerShell? Block it? Or just configure it?&nbsp;<\/p>\n<p>&#8220;Cybersecurity authorities from the United States, New Zealand, and the United Kingdom recommend proper configuration and monitoring of PowerShell, as opposed to removing or disabling PowerShell entirely,&#8221; <a href=\"https:\/\/media.defense.gov\/2022\/Jun\/22\/2003021689\/-1\/-1\/1\/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF\" target=\"_blank\" rel=\"noopener\">the agencies say<\/a>.<\/p>\n<p>&#8220;This will provide benefits from the security capabilities PowerShell can enable while reducing the likelihood of malicious actors using it undetected after gaining access into victim networks.&#8221;<\/p>\n<p>PowerShell&#8217;s extensibility, and the fact that it ships with Windows 10 and 11, gives attackers a means to abuse the tool. This typically happens after an attacker has gained access to a victim&#8217;s network through Windows or other software vulnerabilities.&nbsp;<\/p>\n<p>But PowerShell attacks have caused some admins to remove it from devices and this is a bad idea, according to the NSA. &nbsp;<\/p>\n<p>&#8220;This has prompted some net defenders to disable or remove the Windows tool. NSA and its partners advise against doing so,&#8221; <a href=\"https:\/\/www.nsa.gov\/Press-Room\/Press-Releases-Statements\/Press-Release-View\/Article\/3069620\/nsa-partners-recommend-properly-configuring-monitoring-powershell-in-new-report\/\" target=\"_blank\" rel=\"noopener\">the NSA said<\/a>.&nbsp;<\/p>\n<p>As the <a href=\"https:\/\/media.defense.gov\/2022\/Jun\/22\/2003021689\/-1\/-1\/1\/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF\" target=\"_blank\" rel=\"noopener\">US Department of Defense notes<\/a>, blocking PowerShell hinders defensive capabilities that current versions of PowerShell can provide, and prevents components of Windows from running properly.<\/p>\n<p>The advice aligns with Microsoft&#8217;s guidance on the use of PowerShell and tips it&#8217;s given to admins to protect themselves against PowerShell attacks. Microsoft in 2020 acknowledged that &#8220;PowerShell is being used by both commodity malware and attackers alike&#8221;.&nbsp;<\/p>\n<p>&#8220;PowerShell is \u2013 by far \u2013 the most securable and security-transparent shell, scripting language, or programming language available,&#8221; <a href=\"https:\/\/devblogs.microsoft.com\/powershell\/defending-against-powershell-attacks\/\" target=\"_blank\" rel=\"noopener\">Microsoft said in a 2020 blogpost<\/a>.&nbsp;<\/p>\n<p>New Zealand National Cyber Security Centre sums up the benefits of using PowerShell:&nbsp;<\/p>\n<ul>\n<li>Credential protection during PowerShell remoting<\/li>\n<li>Network protection of PowerShell remoting<\/li>\n<li>Anti-malware Scan Interface (AMSI) integration<\/li>\n<li>Constrained PowerShell with Application Control<\/li>\n<\/ul>\n<p>PowerShell also enables remote admin capabilities that use Kerberos or New Technology LAN Manager (NTLM) protocols. Kerberos is the main framework for on-premises Active Directory (AD), Microsoft&#8217;s identity service, and is the successor to NTLM, which was implemented in Windows 2000.&nbsp;<\/p>\n<p>Microsoft <a href=\"https:\/\/www.zdnet.com\/article\/microsofts-powershell-7-is-generally-available\/\" rel=\"follow\">released PowerShell 7 in 2020<\/a>, but version 5.1 ships with Windows 10 and above. The latest version is 7.2, which includes new security measures like prevention, detection and authentication.<\/p>\n<p>The authorities recommend &#8220;explicitly disabling and uninstalling&#8221; PowerShell 5.1, but they make no recommendations for using PowerShell versions with Linux and macOS. &nbsp;<\/p>\n<p><strong>SEE:&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/why-cloud-security-matters-and-why-you-cant-ignore-it\/#link=%7B%22role%22:%22standard%22,%22href%22:%22https:\/\/www.zdnet.com\/article\/why-cloud-security-matters-and-why-you-cant-ignore-it\/%22,%22target%22:%22_blank%22,%22absolute%22:%22%22,%22linkText%22:%22%3Cstrong%3EWhy%20cloud%20security%20matters%20and%20why%20you%20can't%20ignore%20it%3C\/strong%3E%22%7D\" rel=\"follow\">Why cloud security matters and why you can&#8217;t ignore it<\/a><\/strong><\/p>\n<p>They also offer advice for network protection, AMSI, and configuring AppLocker\/Windows Defender Application Control (WDAC) for configuring PowerShell to prevent attackers gaining full control over PowerShell sessions.&nbsp;<\/p>\n<p>The agencies highlight features available in the latest versions of PowerShell, such as deep script block logging, over-the-shoulder transcription, authentication procedures, and remote access over Secure Shell (SSH) &nbsp;<\/p>\n<p>&#8220;PowerShell is essential to secure the Windows operating system, especially since newer versions have resolved previous limitations and concerns through updates and enhancements,&#8221; the NSA says.&nbsp;<\/p>\n<p>&#8220;Removing or improperly restricting PowerShell would prevent administrators and defenders from utilizing PowerShell to assist with system maintenance, forensics, automation, and security. PowerShell, along with its administrative abilities and security measures, should be managed properly and adopted.&#8221;<\/p>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PowerShell is often abused by attackers but defenders should not switch off the Windows command-line tool, warn cybersecurity agencies.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-47223","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NSA, CISA say: Don&#039;t block PowerShell, here&#039;s what to do instead 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSA, CISA say: Don&#039;t block PowerShell, here&#039;s what to do instead 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-23T10:14:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"NSA, CISA say: Don&#8217;t block PowerShell, here&#8217;s what to do instead\",\"datePublished\":\"2022-06-23T10:14:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\"},\"wordCount\":691,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\",\"name\":\"NSA, CISA say: Don't block PowerShell, here's what to do instead 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\",\"datePublished\":\"2022-06-23T10:14:43+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSA, CISA say: Don&#8217;t block PowerShell, here&#8217;s what to do instead\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSA, CISA say: Don't block PowerShell, here's what to do instead 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","og_locale":"en_US","og_type":"article","og_title":"NSA, CISA say: Don't block PowerShell, here's what to do instead 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-06-23T10:14:43+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"NSA, CISA say: Don&#8217;t block PowerShell, here&#8217;s what to do instead","datePublished":"2022-06-23T10:14:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/"},"wordCount":691,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","url":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","name":"NSA, CISA say: Don't block PowerShell, here's what to do instead 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","datePublished":"2022-06-23T10:14:43+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#primaryimage","url":"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/","contentUrl":"https:\/\/www.zdnet.com\/article\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/nsa-cisa-say-dont-block-powershell-heres-what-to-do-instead\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"NSA, CISA say: Don&#8217;t block PowerShell, here&#8217;s what to do instead"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47223"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47223\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}