Skip to content

Opening book details…

Can I read PowerShell Execution Threat Analysis on EtoBox?

PowerShell Execution Threat Analysis by Đặng Ngọc Chiến is a document available to read on EtoBox.

What is PowerShell Execution Threat Analysis about?

The document outlines a Threat Hunter Playbook focused on detecting local PowerShell execution by adversaries in an environment. It includes various analytics and queries to identify suspicious PowerShell activities, along with references to datasets and known bypasses. The playbook emphasizes the importance of understanding normal PowerShell usage to differentiate between legitimate and malicious activity.

Author
Đặng Ngọc Chiến
Language
EN