Analyzing Powershell Script Block Logging

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.

mukul975 Updated 24.6k repo stars

File contents

mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/analyzing-powershell-script-block-logging commit 673da1f3b0

Frequently asked questions

npx skillmds@latest add mukul975/analyzing-powershell-script-block-logging