Detecting Suspicious Powershell Execution

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

xalgord d2ec922 4.2 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-hunting/detecting-suspicious-powershell-execution commit d2ec922ca2

Frequently asked questions

npx skillmds@latest add xalgord/detecting-suspicious-powershell-execution