Skip to content
Back to skills

Detecting Suspicious Powershell Execution

ASecurity

Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands,

  • 67 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
researchshellsecurity

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills --skill detecting-suspicious-powershell-execution --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Detecting Suspicious Powershell Execution?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Detecting Suspicious Powershell Execution
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/costrict-plugins-repo-detecting-suspicious-powershell-execution/badge)](https://www.skillsdirectory.com/skills/costrict-plugins-repo-detecting-suspicious-powershell-execution)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: detecting-suspicious-powershell-execution
description: Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands,
  download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry
  (CrowdStrike, Microsoft Defender for Endpoint), Sysmon, and SIEM queries (Splunk, Elastic).
  Use when proactively threat hunting, triaging EDR/SIEM alerts, or scoping an incident
  involving malicious PowerShell activity.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- powershell
- execution
- t1059
- amsi
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1059.001
- T1027.010
- T1620
- T1105
---

# Detecting Suspicious Powershell Execution

## When to Use

- When proactively hunting for indicators of detecting suspicious powershell execution in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises

## Prerequisites

- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation

## Workflow

1. **Formulate Hypothesis**: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
2. **Identify Data Sources**: Determine which logs and telemetry are needed to validate or refute the hypothesis.
3. **Execute Queries**: Run detection queries against SIEM and EDR platforms to collect relevant events.
4. **Analyze Results**: Examine query results for anomalies, correlating across multiple data sources.
5. **Validate Findings**: Distinguish true positives from false positives through contextual analysis.
6. **Correlate Activity**: Link findings to broader attack chains and threat actor TTPs.
7. **Document and Report**: Record findings, update detection rules, and recommend response actions.

## Key Concepts

| Concept | Description |
|---------|-------------|
| T1059.001 | PowerShell |
| T1059.003 | Windows Command Shell |
| T1562.001 | Disable or Modify Tools |

## Tools & Systems

| Tool | Purpose |
|------|---------|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |

## Common Scenarios

1. **Scenario 1**: Base64 encoded PowerShell command launched by macro document
2. **Scenario 2**: IEX download cradle fetching payload from C2 server
3. **Scenario 3**: AMSI bypass via reflection patching before payload execution
4. **Scenario 4**: PowerShell Empire agent communicating with C2

## Output Format

```
Hunt ID: TH-DETECT-[DATE]-[SEQ]
Technique: T1059.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
```

Files in this skill

  • LICENSE11 KB
  • SKILL.md3.6 KB
  • assets/template.md2.6 KB
  • references/api-reference.md2.5 KB
  • references/standards.md1.6 KB
  • references/workflows.md2.9 KB
  • scripts/agent.py5.9 KB
  • scripts/process.py3.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…