PowerShell Add-Type WinAPI tamper/injection scaffold

WINDOWS_PS_ADDTYPE_WINAPI_TAMPER

← All detection heuristics · Script

critical WINDOWS_PS_ADDTYPE_WINAPI_TAMPER

What it means

PowerShell embeds C# P/Invoke code for suspicious WinAPI process/window/shell operations.

Why it fires

The file contains PowerShell Add-Type source that compiles C# with DllImport declarations for multiple Windows APIs used in process memory access, window discovery, or shell notification tampering. This is executable script behavior and should be treated as a Windows script artifact even if the file extension or submitted type claims it is a document.

Other Script heuristics

SCRIPT_WSH_OBFUSCATED LNK_POWERSHELL_BIGINT_NETWORK_ENDPOINT WINDOWS_PS_SCREENSHOT_UPLOAD_EXFIL WINDOWS_SCRIPT_CERTUTIL_RUNDLL_CHAIN SCRIPT_WSH_STREAM_WRITE_RUN_CHAIN WINDOWS_SCHEDULED_TASK_SCRIPT_EXEC WINDOWS_SCRIPT_BASE64_BINARY_DROPPER LNK_SCRIPT_DOWNLOADER MACOS_ZSH_LOADER SCRIPT_HEAVY_STRING_DECODER_OBFUSCATION SCRIPT_WSH_MASQUERADE LNK_HIDDEN_SCRIPT_EXEC