MITRE ATT&CK · T1059.001 · PowerShell

PowerShell Detection
Engineering Lab

Detecting attacker abuse of PowerShell before privilege escalation or persistence.

Mission — interrupt attacker progression early by detecting suspicious PowerShell behavior using Windows-native logging, Sysmon, Wazuh, and analyst-driven log interpretation.

Detections
16
Phases
3
Telemetry sources
6
Avg confidence
84 / 100
// tools used in the detection lifecycle

Every tool in this lab supports the cycle

Learn, Build, Secure, Test, Improve — each phase has a purpose and a toolset.

See the full method
Learn
  • · MITRE ATT&CK T1059.001
  • · Windows Internals
  • · IOA concepts
Build
  • · Windows Event Logs
  • · PowerShell Logging
  • · Sysmon
  • · Wazuh Agent
  • · Wazuh Manager
Secure
  • · Group Policy
  • · Windows security policy
  • · Endpoint hardening
Test
  • · Atomic Red Team
  • · Safe PowerShell validation
  • · VMware lab
Improve
  • · Log analysis
  • · Wazuh rule tuning
  • · Detection confidence scoring
  • · ATT&CK chain correlation
Phase 1

Immediate High-Value Detections

Simple, high-signal detections that catch common PowerShell abuse early.

6 labs
Phase 2

Contextual Correlation

Combine PowerShell behavior with surrounding system and network context.

4 labs
Phase 3

Advanced Detection Engineering

Evasive and memory-based tradecraft: AMSI, reflection, entropy, chains.

6 labs