suspicious-powershell-hunt-cross-platform-ideas
Hypothesis-driven hunt plan for suspicious PowerShell, plus query snippets for common telemetry.
$ Installer
git clone https://github.com/tsale/awesome-dfir-skills /tmp/awesome-dfir-skills && cp -r /tmp/awesome-dfir-skills/skills/hunting/suspicious-powershell-hunt ~/.claude/skills/awesome-dfir-skills// tip: Run this command in your terminal to install the skill
Repository

tsale
Author
tsale/awesome-dfir-skills/skills/hunting/suspicious-powershell-hunt
2
Stars
1
Forks
Updated1d ago
Added6d ago