解析 PowerShell 脚本块日志

原名:analyzing-powershell-script-block-logging

从 EVTX 文件中解析 Windows PowerShell 脚本块日志(事件 ID 4104)。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.2 / 5

内容概览

- When investigating security incidents that require analyzing powershell script block logging - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Familiarity with security operations concepts and tools - Access to a test or lab environment for safe execution - Python 3.8+ with required dependencies installed - Appropriate authorization for any testing activities 1. Install dependencies: pip install python-evtx lxml 2. Collect PowerShell Operational logs: Microsoft-Windows-PowerShell%4Operational.evtx 3. Parse Event ID 4104 entries using python-evtx to extract ScriptBlockText, ScriptBlockId, and MessageNumber/MessageTotal for multi-part script reconstruction. 4. Apply detection heuristics: - Base64-encoded commands (-En…

查看 SKILL 详情