analyzing-powershell-empire-artifacts
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
Source facts
- Repository
- mukul975/Anthropic-Cybersecurity-Skills
- Last source activity
- August 2, 2026 at 16:32
- Detected SKILL.md language
- English
- Stars
- 33,552
- Forks
- 4,068
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.
Showing SKILL.md
- name
- analyzing-powershell-empire-artifacts
- description
- Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
- domain
- cybersecurity
- subdomain
- threat-hunting
- tags
- ["PowerShell-Empire","threat-hunting","Script-Block-Logging","base64","stager","C2","MITRE-ATT&CK","T1059.001","forensics"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"]
- nist_ai_rmf
- ["GOVERN-1.1","MEASURE-2.7","MANAGE-3.1"]
- nist_csf
- ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"]
- mitre_attack
- ["T1059.001","T1071.001","T1003.001","T1558.003","T1027.010"]