PowerShell Proxy-Aware Intercommunication and Manipulation
Jean Rosemond Dora, Ladislav Hluchý · 2025
With the exponential expansion of attacks, organizations and enterprises nowadays, force their network communication through a proxy. This measure can assist security analysts to better control their environment, and monitor traffic. Likewise, attackers are interested in the manipulation techniques of the proxy concept, since they are aware of this protection. On the other hand, penetration testers (also known as, ethical attackers, or hackers) must ensure that their techniques (while generating payloads) can work through proxy to understand better steps that need to be mitigated. Additionally, they can always attempt to manipulate the proxy if possible [1], [2], along with any of its implemented monitors for this purpose. Usually, the PowerShell download cradles may not always be proxy-aware. However, the Meterpreter HTTP and HTTPS are [3]. A Meterpreter is a Metasploit attack payload that provides an interactive shell from which an attacker can proceed with his exploration of the target machine and run codes. Our focus will be based on strategies to talk to a proxy, i.e., we will need to use some modules which by default, are proxy-aware in the creation of our payloads [4]. We may still face some issues with some classes that are proxy-aware, since they may be reverted in future versions of Windows.