This is the first in a new series from offensive security experts at X-Force Red sharing research, resources and recommendations to help you harden your defenses. Attackers have been migrating from PowerShell to C# for post-exploitation toolkits due to advances in security product configurations and features. The majority of detections for these C# tools rely on static signatures, rather than the behaviors of the tools themselves. This blog post will review various static indicators that can be used within C# tool kits for detection, and how to bypass those static signatures.”]