PowerShell Detection
Detecting malicious PowerShell use through behavioral signals like encoded commands, suspicious script content, unusual parent processes, and known abuse patterns, often mapped to ATT&CK to catch a heavily abused execution technique.
Concept Neighborhood
Start here
Endpoint Telemetry
The foundation PowerShell Detection builds on, worth understanding first.
Command Line
6
lessons
Parent Process
6
lessons
LOLBin Detection
5
lessons
LSASS Memory Dumping Detection
5
lessons
MITRE ATT&CK Framework
5
lessons
HKCU
3
lessons
Show 1 more connection
Related Lessons
5 lessons cover this conceptBuild Endpoint Behavior Analytics
SOC Analyst
Use ATT&CK Without Overclaiming Coverage
SOC Analyst
From Hypothesis to Telemetry Contract
SOC Analyst
Correlate Identity, Remote Access, and Network Behavior
SOC Analyst
Engineer Rules, Tuning, and Response Contracts
SOC Analyst
Sign in to open lesson content directly.
