suspicious-powershell-hunt-cross-platform-ideas

Hypothesis-driven hunt plan for suspicious PowerShell, plus query snippets for common telemetry.

$ Installer

git clone https://github.com/tsale/awesome-dfir-skills /tmp/awesome-dfir-skills && cp -r /tmp/awesome-dfir-skills/skills/hunting/suspicious-powershell-hunt ~/.claude/skills/awesome-dfir-skills

// tip: Run this command in your terminal to install the skill