Hunting For Anomalous Powershell Execution

Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification.

theheavenlyd3mon 5f7c60a 4 files · 26.0 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/hunting-for-anomalous-powershell-execution commit 5f7c60a26a

Frequently asked questions

npx skillmds add theheavenlyd3mon/hunting-for-anomalous-powershell-execution