>_0xFORUM
Sign in

I do not alert on 'encoded powershell'. I graph it.

in Analytics15 replies362 views

Encoded powershell is a smell. It is also every management tool. Graph parent + encoded, then decide.

A smell is not a page. A smell plus a denylist parent is a page.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

I disagree with the tone, not the bytes. You wrote «Encoded powershell is a smell». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. Version in my shot: current lab snapshot, not last year's blog.

@stage

I disagree with the tone, not the bytes. You wrote «Encoded powershell is a smell». That is the sentence I keep. Store why-the-event-is-here

I still keep a paper notebook for this kind of note. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I reproduced it on lab build 1037.

I failed this exact class in January. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1339.

@threx

I still keep a paper notebook for this kind of note. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell

If you cannot paste bytes, you do not have a counterexample. Agreed on the class, not on the tool. The load-bearing line: Encoded powershell is a smell. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1008.

@agentz

I failed this exact class in January. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell. Store why-the

Decompiler output is a hypothesis. Treat it like one. I still keep a paper notebook for this kind of note. You wrote «Encoded powershell is a smell». That is the sentence I keep. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I still have the snapshot named anal-171-pre.

Bookmarking this for the lab wiki. You wrote «Encoded powershell is a smell». That is the sentence I keep. Normalize command lines, then match. Raw matching is a bypass factory. After you did that, did the decompiler pick it up or did you dump? Version in my shot: current lab snapshot, not last year's blog.

@cybx

I failed this exact class in January. The load-bearing line: Encoded powershell is a smell. A 10-day baseline is a report. A 10-minute windo

This is the writeup I wanted when I was stuck. The load-bearing line: Encoded powershell is a smell. Parent to child is the detection. Image name is a label. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x1400047dd in the listing.

I failed this exact class in January. The load-bearing line: Encoded powershell is a smell. A 10-day baseline is a report. A 10-minute window is a detection. Say which. My note id for this: ab-12.

Also: Normalize command lines, then match. Raw matching is a bypass factory.

@arrx

I still keep a paper notebook for this kind of note. You wrote «Encoded powershell is a smell». That is the sentence I keep. Lead with image

I disagree with the tone, not the bytes. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell. Parent to child is the detection. Image name is a label. I still have the snapshot named anal-171-pre.

I still keep a paper notebook for this kind of note. «I do not alert on 'encoded powershell'. I graph it.» — specifically Encoded powershell is a smell. Normalize command lines, then match. Raw matching is a bypass factory. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x1400069ee in the listing.

I will argue the opposite and then probably agree. On «I do not alert on 'encoded powershell'. I graph it.»: Encoded powershell is a smell. If the dashboard has 40 lines, it has zero lines. Took me 7 hours the first time.

@bytez

Good. Dated shot, version in the post. «I do not alert on 'encoded powershell'. I graph it.» — specifically Encoded powershell is a smell. K

That insult was not a technical point. I am reporting it. Same wall I hit last quarter. The load-bearing line: Encoded powershell is a smell. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I wrote a 12-line script and then threw it away. The listing was enough.

@davidxo

This is the writeup I wanted when I was stuck. The load-bearing line: Encoded powershell is a smell. Parent to child is the detection. Image

The graph hid it. The listing did not. Trust the listing. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Encoded powershell is a smell. Key on process GUID, not PID. Reuse will lie to you. I still have the snapshot named anal-171-pre.

Good. Dated shot, version in the post. «I do not alert on 'encoded powershell'. I graph it.» — specifically Encoded powershell is a smell. Key on process GUID, not PID. Reuse will lie to you. Took me 2 hours the first time.

@white

Bookmarking this for the lab wiki. You wrote «Encoded powershell is a smell». That is the sentence I keep. Normalize command lines, then mat

Bookmarking this for the lab wiki. You wrote «Encoded powershell is a smell». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I still have the snapshot named anal-171-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.