← All detection heuristics · Script
critical
WINDOWS_PS_ADDTYPE_WINAPI_TAMPER
What it means
PowerShell embeds C# P/Invoke code for suspicious WinAPI process/window/shell operations.
Why it fires
The file contains PowerShell Add-Type source that compiles C# with DllImport declarations for multiple Windows APIs used in process memory access, window discovery, or shell notification tampering. This is executable script behavior and should be treated as a Windows script artifact even if the file extension or submitted type claims it is a document.
Other Script heuristics
SCRIPT_WSH_OBFUSCATED LNK_POWERSHELL_BIGINT_NETWORK_ENDPOINT WINDOWS_PS_SCREENSHOT_UPLOAD_EXFIL WINDOWS_SCRIPT_CERTUTIL_RUNDLL_CHAIN SCRIPT_WSH_STREAM_WRITE_RUN_CHAIN WINDOWS_SCHEDULED_TASK_SCRIPT_EXEC WINDOWS_SCRIPT_BASE64_BINARY_DROPPER LNK_SCRIPT_DOWNLOADER MACOS_ZSH_LOADER SCRIPT_HEAVY_STRING_DECODER_OBFUSCATION SCRIPT_WSH_MASQUERADE LNK_HIDDEN_SCRIPT_EXEC