BigHugger
sk Skill · mukul975

analyzing-powershell-empire-artifacts

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
PythonforensicsT1059.001MITRE-ATT&CKstagerC2base64Script-Block-Loggingthreat-huntingPowerShell-Empire
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python