title:DNSCat2 Powershell Implementation Detection Via Process Creation
id:b11d75d6-d7c1-11ea-87d0-0242ac130003
status:experimental
description:The PowerShell implementation of DNSCat2 calls nslookup to craft queries. Counting nslookup processes spawned by PowerShell will show hundreds or thousands of instances if PS DNSCat2 is active locally.