Skill Market

analyzing powershell empire artifacts

Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,

GitHub
githubcommunityai-agentsclaude-codecloud-securitycybersecuritydevsecopsethical-hacking
0.0
0 installs33.4K GitHub starsby mukul975

Skill Introduction

Overview
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,

Core value

Turns reusable Debugging know-how into an installable skill, helping users complete github, community, ai-agents, claude-code work faster.

Target users

  • Developers, testers, and maintainers who handle Debugging tasks in Focus Code.
  • Teams that already trust workflows or content from mukul975.
  • Users who want standardized prompts, steps, or conventions instead of repeating setup work.

Best practices

  • Read the skill content first to confirm required inputs, expected outputs, and dependencies.
  • Try it on a small task before relying on it for critical work.
  • Add project-specific constraints such as coding style, target platform, test expectations, and delivery format.
  • For external sources, verify the source link, version, and recent maintenance activity.

Best use cases

  • Tasks related to github, community, ai-agents, claude-code that need a reusable execution flow.
  • Converting a community repo, team convention, or personal workflow into day-to-day assistance.
  • Starting from a proven skill instead of writing prompts or procedures from scratch.

Limits and boundaries

  • Results depend on the quality of the original skill content and may need human correction.
  • It does not replace code review, tests, security review, or professional judgment.
  • External tools, APIs, account permissions, and local dependencies still need separate setup.

Differentiation

  • Structured around Debugging, making it easier to discover and reuse than loose prompt snippets.
  • Marked as GitHub, which helps users judge trust and maintenance expectations.
  • Keeps the original source link available for repository, documentation, or discussion follow-up.
  • Tagged with github, community, ai-agents, claude-code, so it can be filtered by concrete task intent.

Install and use

Install
Copy Install Command
focus install analyzing-powershell-empire-artifacts-4efb1e
View source

Detail Preview

SKILL.md

Primary filemarkdown3 KB

name: analyzing-powershell-empire-artifacts description: Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events. domain: cybersecurity subdomain: threat-hunting tags:

  • PowerShell-Empire
  • threat-hunting
  • Script-Block-Logging
  • base64
  • stager
  • C2
  • MITRE-ATT&CK
  • T1059.001
  • forensics version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques:
  • Executable Denylisting
  • Execution Isolation
  • File Metadata Consistency Validation
  • Content Format Conversion
  • File Content Analysis nist_ai_rmf:
  • GOVERN-1.1
  • MEASURE-2.7
  • MANAGE-3.1 nist_csf:
  • DE.CM-01
  • DE.AE-02
  • DE.AE-07
  • ID.RA-05

Analyzing PowerShell Empire Artifacts

Overview

PowerShell Empire is a post-exploitation framework consisting of listeners, stagers, and agents. Its artifacts leave detectable traces in Windows event logs, particularly PowerShell Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103). This skill analyzes event logs for Empire's default launcher string (powershell -noP -sta -w 1 -enc), Base64 encoded payloads containing System.Net.WebClient and FromBase64String, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast, Invoke-TokenManipulation), and staging URL patterns.

When to Use

  • When investigating security incidents that require analyzing powershell empire artifacts
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.9+ with access to Windows Event Log or exported EVTX files
  • PowerShell Script Block Logging (Event ID 4104) enabled via Group Policy
  • Module Logging (Event ID 4103) enabled for comprehensive coverage

Key Detection Patterns

  1. Default launcher — powershell -noP -sta -w 1 -enc followed by Base64 blob
  2. Stager indicators — System.Net.WebClient, DownloadData, DownloadString, FromBase64String
  3. Module signatures — Invoke-Mimikatz, Invoke-Kerberoast, Invoke-TokenManipulation, Invoke-PSInject, Invoke-DCOM
  4. User agent strings — default Empire user agents in HTTP listener configuration
  5. Staging URLs — /login/process.php, /admin/get.php and similar default URI patterns

Output

JSON report with matched IOCs, decoded Base64 payloads, timeline of suspicious events, MITRE ATT&CK technique mappings, and severity scores.

Reviews

Overall rating

0.0
0.0

0 comments

No reviews yet