Detecting Suspicious Powershell Execution

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

theheavenlyd3mon 4051c1a 8 files · 33.1 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-suspicious-powershell-execution commit 4051c1a783

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-suspicious-powershell-execution