sk Skill · meltedinhex
hunting-suspicious-powershell-execution
Hunts malicious PowerShell using script-block (EID 4104) and module logging: scoring encoded commands, download cradles, AMSI/logging bypass, and in-memory execution, then decoding payloads for triage. Activates for requests to hunt malicious PowerShell, analyze script-block logs, or detect encoded command abuse.
Open on skills.sh ↗read 2026-09-15
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
bashPythondetectionlolbinwindowspowershellscript-block-loggingthreat-hunting
- Host repository
- meltedinhex/analyst-ai-pack
- Version
- 1.0.0
- Licence
- Apache-2.0
- Host stars
- 22
- Host language
- Python