hunting-for-anomalous-powershell-execution
mukul975/Anthropic-Cybersecurity-Skills
Hunts malicious PowerShell activity by parsing EVTX exports of Script Block Logging, Module Logging, and process events to surface encoded commands, obfuscation, AMSI bypass attempts, download cradles, and credential-stealing behaviors.