1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / tool

Invoke-PSImage — Attack Tool

Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords.

Tool identity and evidence

Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.

Aliases: Invoke-PSImage

Primary tool reference

Existing author guides

No reviewed association in this snapshot.

Primary documentation

No reviewed association in this snapshot.

Connected ecosystem references

Linked tags

Documented actor use

Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.

Technique-specific simulations and detections

Detection links describe the associated behavior, not independently verified tool-specific signatures.

Telemetry context

Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.