hunting-for-anomalous-powershell-execution
mukul975/Anthropic-Cybersecurity-Skills
Analyzes PowerShell EVTX logs to flag obfuscated script block execution, encoded commands, AMSI bypass attempts, download cradles, credential dumping keywords, and other anomalous behaviors, helping SOC analysts and threat hunters prioritize findings.