tsale

Suspicious PowerShell hunt (cross-platform ideas)

"Hypothesis-driven hunt plan for suspicious PowerShell, plus query snippets for common telemetry."

tsale 314 33 Updated 5mo ago
GitHub

Install

npx skillscat add tsale/awesome-dfir-skills/suspicious-powershell-hunt-cross-platform-ideas

Install via the SkillsCat registry.