Detecting Suspicious Powershell Execution

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

26zl 809e747 8 files · 33.1 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-suspicious-powershell-execution commit 809e747a9a

Frequently asked questions

npx skillmds@latest add 26zl/detecting-suspicious-powershell-execution