Detecting Suspicious Powershell Execution

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

yanacuti1121 df38fa9 8 files · 33.1 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/detecting-suspicious-powershell-execution commit df38fa94f0

Frequently asked questions

npx skillmds add yanacuti1121/detecting-suspicious-powershell-execution