detecting-suspicious-powershell-execution
mukul975/Anthropic-Cybersecurity-Skills
A comprehensive guide and workflow for threat hunting suspicious PowerShell activity (T1059.001). This technique focuses on detecting advanced adversary techniques such as encoded commands, AMSI bypass, and download cradles using telemetry from EDR platforms (CrowdStrike, MDE), SIEMs (Splunk, Elastic), and Sysmon. Essential for proactive threat detection, incident response, and security assessment.