What it does. Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-suspicious-powershell-execution, or copy the skill folder into ~/.claude/skills/detecting-suspicious-powershell-execution/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-suspicious-powershell-execution/SKILL.md
SKILL.md (verbatim)
name: detecting-suspicious-powershell-execution
description: Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands,
download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry
(CrowdStrike, Microsoft Defender for Endpoint), Sysmon, and SIEM queries (Splunk, Elastic).
Use when proactively threat hunting, triaging EDR/SIEM alerts, or scoping an incident
involving malicious PowerShell activity.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- powershell
- execution
- t1059
- amsi
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1059.001
- T1027.010
- T1620
- T1105
Detecting Suspicious Powershell Execution
When to Use
- When proactively hunting for indicators of detecting suspicious powershell execution in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept |
Description |
| T1059.001 |
PowerShell |
| T1059.003 |
Windows Command Shell |
| T1562.001 |
Disable or Modify Tools |
| Tool |
Purpose |
| CrowdStrike Falcon |
EDR telemetry and threat detection |
| Microsoft Defender for Endpoint |
Advanced hunting with KQL |
| Splunk Enterprise |
SIEM log analysis with SPL queries |
| Elastic Security |
Detection rules and investigation timeline |
| Sysmon |
Detailed Windows event monitoring |
| Velociraptor |
Endpoint artifact collection and hunting |
| Sigma Rules |
Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Base64 encoded PowerShell command launched by macro document
- Scenario 2: IEX download cradle fetching payload from C2 server
- Scenario 3: AMSI bypass via reflection patching before payload execution
- Scenario 4: PowerShell Empire agent communicating with C2
Hunt ID: TH-DETECT-[DATE]-[SEQ]
Technique: T1059.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
Other files in this skill
assets/template.md (verbatim)
Detecting Suspicious Powershell Execution - Hunt Template
| Field |
Value |
| Hunt ID |
TH-DETECT-YYYY-MM-DD-NNN |
| Analyst |
|
| Date Started |
|
| Date Completed |
|
| Status |
[ ] In Progress / [ ] Complete |
| Priority |
[ ] Critical / [ ] High / [ ] Medium / [ ] Low |
Hypothesis
Statement: [Formulate a clear, testable hypothesis]
Basis: [ ] Threat Intel / [ ] ATT&CK Gap / [ ] Anomaly / [ ] Incident Follow-up
Target Techniques
Data Sources
Queries Executed
Query 1: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Query 2: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Findings
| # |
Timestamp |
Host |
User |
Technique |
Evidence Summary |
Risk |
Verdict |
| 1 |
|
|
|
|
|
|
TP / FP / BTP |
| 2 |
|
|
|
|
|
|
TP / FP / BTP |
| 3 |
|
|
|
|
|
|
TP / FP / BTP |
IOCs Discovered
Network IOCs
| Type |
Value |
Context |
Confidence |
| IP |
|
|
|
| Domain |
|
|
|
| URL |
|
|
|
Host IOCs
| Type |
Value |
Context |
Confidence |
| SHA256 |
|
|
|
| Filename |
|
|
|
| Registry Key |
|
|
|
| Scheduled Task |
|
|
|
Hunt Results Summary
| Metric |
Count |
| Total Events Analyzed |
|
| Anomalies Identified |
|
| True Positives |
|
| False Positives |
|
| Benign True Positives |
|
| New IOCs Discovered |
|
| Detection Rules Created |
|
| Detection Rules Updated |
|
Hypothesis Outcome
Recommendations
- Immediate Actions: [Containment, remediation steps]
- Detection Improvements: [New rules, tuning recommendations]
- Visibility Gaps: [Missing data sources, coverage needs]
- Security Hardening: [Configuration changes, policy updates]
- Follow-up Hunts: [Related hypotheses to investigate]
Analyst Notes
[Free-form notes, observations, and lessons learned]
references/api-reference.md (verbatim)
API Reference: Suspicious PowerShell Execution Detection
Windows PowerShell Event Logs
Event IDs
| Event ID |
Log |
Description |
| 4104 |
PowerShell/Operational |
Script block logging |
| 4103 |
PowerShell/Operational |
Module logging |
| 800 |
PowerShell |
Pipeline execution details |
| 400 |
PowerShell |
Engine lifecycle (start) |
| 403 |
PowerShell |
Engine lifecycle (stop) |
Script Block Logging Query
Get-WinEvent -FilterHashtable @{
LogName = 'Microsoft-Windows-PowerShell/Operational'
Id = 4104
} -MaxEvents 100
Event 4104 Properties
| Index |
Field |
Description |
| 0 |
MessageNumber |
Block sequence number |
| 1 |
MessageTotal |
Total blocks in script |
| 2 |
ScriptBlockText |
Actual script content |
| 3 |
ScriptBlockId |
Unique script ID |
| 4 |
Path |
Script file path |
Suspicious PowerShell Patterns
Execution Policy Bypass
powershell -ExecutionPolicy Bypass -File script.ps1
powershell -ep bypass -nop -w hidden -enc <base64>
Common Obfuscation Techniques
| Technique |
Example |
| Concatenation |
"Inv"+"oke-Ex"+"pression" |
| Variable substitution |
${Invoke-Expression} |
| Encoded commands |
-enc SQBuAHYAbwBrAGUALQA... |
| Char array |
[char[]]@(73,69,88) -join '' |
Sigma Detection Rules
Suspicious PowerShell Command Line
title: Suspicious PowerShell Invocation
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '-enc'
- '-EncodedCommand'
- 'FromBase64String'
- 'DownloadString'
- 'Invoke-Expression'
condition: selection
level: high
AMSI (Antimalware Scan Interface)
AMSI Scan Functions
HRESULT AmsiScanBuffer(
HAMSICONTEXT amsiContext,
PVOID buffer,
ULONG length,
LPCWSTR contentName,
HAMSISESSION amsiSession,
AMSI_RESULT *result
);
AMSI Results
| Value |
Meaning |
| 0 |
Clean |
| 1 |
Not Detected |
| 16384 |
Blocked by admin |
| 32768 |
Detected (malware) |
Microsoft Defender ATP API
Advanced Hunting Query
POST https://api.security.microsoft.com/api/advancedqueries/run
Authorization: Bearer {token}
{
"Query": "DeviceProcessEvents | where FileName == 'powershell.exe' | where ProcessCommandLine has_any('encodedcommand','downloadstring','invoke-expression') | project Timestamp, DeviceName, ProcessCommandLine | take 100"
}
references/standards.md (verbatim)
Standards and References - Detecting Suspicious Powershell Execution
MITRE ATT&CK Mappings
| Technique |
Name |
Description |
| T1059.001 |
PowerShell |
See attack.mitre.org/techniques/T1059/001 |
| T1059.003 |
Windows Command Shell |
See attack.mitre.org/techniques/T1059/003 |
| T1562.001 |
Disable or Modify Tools |
See attack.mitre.org/techniques/T1562/001 |
Detection Data Sources
| Source |
Event ID |
Purpose |
| Sysmon |
1 |
Process creation with command line |
| Sysmon |
3 |
Network connection initiated |
| Sysmon |
7 |
Image loaded (DLL) |
| Sysmon |
10 |
Process access (LSASS) |
| Sysmon |
11 |
File creation |
| Sysmon |
12/13 |
Registry create/set |
| Sysmon |
22 |
DNS query |
| Sysmon |
25 |
Process tampering |
| Windows Security |
4624 |
Successful logon |
| Windows Security |
4625 |
Failed logon |
| Windows Security |
4648 |
Explicit credential logon |
| Windows Security |
4672 |
Special privileges assigned |
| Windows Security |
4688 |
Process creation |
| Windows Security |
4697 |
Service installed |
| Windows Security |
4698 |
Scheduled task created |
| Windows Security |
4769 |
Kerberos TGS requested |
| Windows Security |
5140 |
Network share accessed |
References
references/workflows.md (verbatim)
Detailed Hunting Workflow - Detecting Suspicious Powershell Execution
Phase 1: Data Collection and Querying
Splunk SPL Query
index=sysmon EventCode=1 Image="*\\powershell.exe"
| where match(CommandLine, "(?i)(-enc|-encodedcommand|-w hidden|-nop|iex|invoke-expression|downloadstring|webclient|bypass)")
| table _time Computer User CommandLine ParentImage
KQL Query (Microsoft Defender for Endpoint)
DeviceProcessEvents
| where FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("-enc","-encodedcommand","-w hidden","iex","downloadstring","bypass")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName
Phase 2: Baseline and Anomaly Detection
Step 2.1 - Establish Normal Behavior Baseline
- Collect 30 days of historical data for the targeted technique
- Document expected patterns, frequencies, and legitimate use cases
- Identify known false positive sources and document exceptions
- Build statistical baseline (mean, standard deviation) for key metrics
Step 2.2 - Identify Anomalies
- Compare current activity against the 30-day baseline
- Flag events exceeding 3 standard deviations from normal
- Prioritize anomalies by risk score and potential business impact
- Cross-reference with threat intelligence for known IOCs
Phase 3: Investigation and Correlation
Step 3.1 - Deep Dive Analysis
- For each anomaly, collect full process tree context
- Correlate with network activity, file operations, and authentication events
- Check binary signatures, file hashes, and certificate validity
- Review user account context and access patterns
Step 3.2 - Attack Chain Reconstruction
- Map findings to MITRE ATT&CK kill chain stages
- Identify initial access vector if applicable
- Trace lateral movement and privilege escalation paths
- Determine data access and potential exfiltration
Phase 4: Validation and Response
Step 4.1 - True/False Positive Determination
- Verify findings with system owners and IT operations
- Check change management records for authorized activities
- Validate user context (authorized actions vs. compromised account)
- Document determination rationale for each finding
Step 4.2 - Response Actions
- For confirmed threats: initiate incident response procedures
- For detection gaps: create or update detection rules
- For false positives: tune existing rules and update exclusions
- Update threat hunting playbook with lessons learned
Phase 5: Documentation and Reporting
Step 5.1 - Hunt Report
- Summarize hypothesis, methodology, and findings
- Include all queries executed and their results
- Document IOCs discovered and detection rules created
- Provide recommendations for security improvements
Step 5.2 - Knowledge Base Update
- Add findings to threat intelligence platform
- Update MITRE ATT&CK coverage heatmap
- Share detection rules via Sigma format
- Schedule follow-up hunts for related techniques
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.