1. joeyaiello, Powershell scripting, https://docs.microsoft.com/en-us/powershell/scripting/overview, 2019 (Retrieved December 8, 2019).
2. D. Bohannon, Invoke-obfuscation, https://github.com/danielbohannon/Invoke-Obfuscation, 2019 (original-date: 2016-09-25T03:38:02Z).
3. A.T.A.O.N.C. Geoff Ackerman, Rick Cole, Overruled: Containing a potentially destructive adversary, https://www.fireeye.com/blog/threat-research/2018/12/overruled-containing-a-potentially-destructive-adversary.html, 2018 (Retrieved December 7, 2019).
4. C. Wueest, The increased use of powershell in attacks, https://www.symantec.com/content/dam/symantec/docs/security-center/white-papers/increased-use-of-powershell-in-attacks-16-en.pdf, 2019 (Retrieved December 7, 2019).
5. Effective and light-weight deobfuscation and semantic-aware attack detection for powershell scripts;Li,2019