Analyzing Powershell Script Block Logging

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression abuse, download cradles, and AMSI bypass attempts.

agentflocks 15a7ce4 5 files · 24.7 KB Updated

File contents

agentflocks/flocks/tree/main/.flocks/flockshub/plugins/skills/Anthropic-Cybersecurity-Skills/analyzing-powershell-script-block-logging commit 15a7ce4fa2

Frequently asked questions

npx skillmds@latest add agentflocks/analyzing-powershell-script-block-logging