BigHugger
sk Skill · meltedinhex

hunting-suspicious-powershell-execution

Hunts malicious PowerShell using script-block (EID 4104) and module logging: scoring encoded commands, download cradles, AMSI/logging bypass, and in-memory execution, then decoding payloads for triage. Activates for requests to hunt malicious PowerShell, analyze script-block logs, or detect encoded command abuse.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythondetectionlolbinwindowspowershellscript-block-loggingthreat-hunting
Host repository
meltedinhex/analyst-ai-pack
Version
1.0.0
Licence
Apache-2.0
Host stars
22
Host language
Python