analyzing-powershell-empire-artifacts
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
ソース情報
- リポジトリ
- mukul975/Anthropic-Cybersecurity-Skills
- ソースの最終更新活動
- 2026年8月2日 16:32
- 検出された SKILL.md の言語
- 英語
- スター
- 33,552
- フォーク
- 4,068
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
SKILL.md を表示中
- name
- analyzing-powershell-empire-artifacts
- description
- Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
- domain
- cybersecurity
- subdomain
- threat-hunting
- tags
- ["PowerShell-Empire","threat-hunting","Script-Block-Logging","base64","stager","C2","MITRE-ATT&CK","T1059.001","forensics"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"]
- nist_ai_rmf
- ["GOVERN-1.1","MEASURE-2.7","MANAGE-3.1"]
- nist_csf
- ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"]
- mitre_attack
- ["T1059.001","T1071.001","T1003.001","T1558.003","T1027.010"]