PowerShell scripts in process memory - .NET assemblies loaded entirely from memory - WMI event subscriptions with embedded scripts - COM object hijacking