analyzing-powershell-empire-artifacts
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
معلومات المصدر
- المستودع
- mukul975/Anthropic-Cybersecurity-Skills
- آخر نشاط في المصدر
- ٢ أغسطس ٢٠٢٦ في ١٦:٣٢
- لغة SKILL.md المكتشفة
- الإنجليزية
- النجوم
- ٣٣٬٥٥٢
- التفرعات
- ٤٬٠٦٨
خيارات التثبيت
يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.
مراجعة ملفات المصدر
اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.
عرض SKILL.md
- name
- analyzing-powershell-empire-artifacts
- description
- Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
- domain
- cybersecurity
- subdomain
- threat-hunting
- tags
- ["PowerShell-Empire","threat-hunting","Script-Block-Logging","base64","stager","C2","MITRE-ATT&CK","T1059.001","forensics"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"]
- nist_ai_rmf
- ["GOVERN-1.1","MEASURE-2.7","MANAGE-3.1"]
- nist_csf
- ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"]
- mitre_attack
- ["T1059.001","T1071.001","T1003.001","T1558.003","T1027.010"]