analyzing-powershell-empire-artifacts
mukul975/Anthropic-Cybersecurity-Skills
This tool is designed for advanced threat hunting and digital forensics. It analyzes Windows Event Logs (specifically Script Block Logging 4104 and Module Logging 4103) to detect artifacts left by the PowerShell Empire post-exploitation framework. Detection patterns include default launchers, Base64 payloads (WebClient, FromBase64String), known module invocations (e.g., Invoke-Mimikatz), and staging URL patterns, helping confirm C2 activity and lateral movement.