Blocking outbound PowerShell traffic using the Windows Firewall
Some malware use PowerShell to download additional components, such as highlighted in the blog posting found at To block outbound traffic using the Windows Firewall, add two rules:
To test the rule, use the command below.
cmd /c PowerShell (New-Object System.Net.Webclient).DownloadFile('','%TMP%\test.txt');
The following commands can be excuted as a test within PowerShell.
$WebClient = New-Object System.Net.WebClient