BigHugger
sk Skill · mukul975

detecting-suspicious-powershell-execution

Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft Defender for Endpoint), Sysmon, and SIEM queries (Splunk, Elastic). Use when proactively threat hunting, triaging EDR/SIEM alerts, or scoping an incident involving malicious PowerShell activity.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonproactive-detectionamsit1059executionpowershellmitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python