PowerShell Encoded Commands: Building Detection Rules That Actually Work (Part 2)
I built Splunk queries in my lab. Hereβs what failed, what worked, and why the -eNcO parameter defeats simple detection.
I just published PowerShell Encoded Commands: Building Detection Rules That Actually Work (Part 2) medium.com/p/powershell...
#infosec #Cyberseurity #ThreatDetection #Analysis #Medium #blog #Powershell #Encoded
03.02.2026 09:28 β π 0 π 0 π¬ 0 π 0
Practical Part is coming soon!! π
28.01.2026 15:53 β π 0 π 0 π¬ 0 π 0
PowerShell Encoded Commands: Why Attackers Love It and How We Hunt It
Theyβre hiding in plain sight in your logs. Hereβs how 100,000+ variations of the same technique keep working.
I just published PowerShell Encoded Commands: Why Attackers Love It and How We Hunt It medium.com/p/powershell...
#Hunt #Cybersecurity #ThreatHunting #Analysis #Powershell #Ecoded #Base64 #Trending #Medium #Blog #bluesky #Redcanary #Paloalto #Mitre #Att&ck
28.01.2026 09:37 β π 1 π 0 π¬ 1 π 0
GitHub - Manishrawat21/soc-automation-lab: Documented SOC automation workflow using Wazuh, N8N, Caldera, and Velociraptor
Documented SOC automation workflow using Wazuh, N8N, Caldera, and Velociraptor - Manishrawat21/soc-automation-lab
Just published a new GitHub repo documenting my SOC automation lab. github.com/Manishrawat2...
It covers detection, alert enrichment, attack simulation, and lessons learned using Wazuh, N8N, Caldera, and Velociraptor, all designed as a learning reference, not a production system.
#cybersecurity
27.01.2026 14:59 β π 0 π 0 π¬ 0 π 0
Catching APT29βs Favorite Evasion Trick: Detecting DLL Sideloading with Sigma (T1574.002)
A multi-tiered detection strategy to uncover one of the stealthiest persistence techniques used by nation-state threat actors.
I just published Catching APT29βs Favorite Evasion Trick: Detecting DLL Sideloading with Sigma (T1574.002) devsecopsai.today/catching-apt...
#Cybersecurity #CISO #APT29 #Sigma #Evasion #Published #Detection #Threat #Medium #Blog #Bluesky #bsky #Analysis
27.01.2026 03:27 β π 1 π 0 π¬ 0 π 0
Thanks James
26.01.2026 10:49 β π 0 π 0 π¬ 0 π 0
How I Built a Sigma Detection Rule to Catch APT29βs Encoded PowerShell Attacks
A deep dive into threat hunting methodology, detection engineering, and building effective defenses against nation-state adversaries
I just published How I Built a Sigma Detection Rule to Catch APT29βs Encoded PowerShell Attacks systemweakness.com/how-i-built-...
#Apt29 #Cybersecurity #ThreatHunting #Threat #Hunting #SIGMA #Sysmon #Medium #Blog #Bluesky #CISO #CTO
26.01.2026 06:54 β π 2 π 0 π¬ 1 π 0
GitHub - Manishrawat21/Analysis: I analyzed some famous attack tecniques here
I analyzed some famous attack tecniques here. Contribute to Manishrawat21/Analysis development by creating an account on GitHub.
Published my DLL hijacking research on GitHub.
GitHub: DLL Hijacking Detection - Theory, Evidence, and Telemetry
37 real Sysmon events. Complete analysis. Open to feedback.
github.com/Manishrawat2...
#ThreatHunting #SecurityResearch #Github #Analysis #Cybersecurity #Windows #Sysmon #Splunk #hack
25.01.2026 05:29 β π 0 π 0 π¬ 0 π 0
37 Sysmon Events. One Complete DLL Hijacking Attack. Hereβs What Happened.
I analyzed real malware logs and discovered why non-admin users can execute code without triggering a single alert.
I just published 37 Sysmon Events. One Complete DLL Hijacking Attack. Hereβs What Happened. medium.com/p/37-sysmon-...
#Splunk #Trending #Cybersecurity #Writer #Hijacking #Medium #Blog #Threat_hunting #Analysis #Sysmon #Windows #CISO #Hunter #Threat #Published #Events
25.01.2026 02:34 β π 3 π 2 π¬ 0 π 0
On Sunday, I'm going to publish a practical version of this. "37 Sysmon Events. One Complete DLL Hijacking Attack. Here's What Happened."
23.01.2026 10:53 β π 0 π 0 π¬ 0 π 0
DLL Hijacking Still Works in 2025 and Thatβs a Problem
Why a decades-old Windows behavior still defeats modern defenses
I just published DLL Hijacking Still Works in 2025 and Thatβs a Problem systemweakness.com/dll-hijackin...
#Cybersecurity #Bsky #Blog #Medium #Trending #ThreatHunter #Malware #Hijacking #Splunk
23.01.2026 10:45 β π 0 π 0 π¬ 1 π 0
Software nerd, cat enthusiast, pixel art noob, gamedev, playing with LLMs
Trust & Safety + a little bit of Paranoia.
Recovering SOC Analyst & Fraud Hunter. I like my bad actors with a side of sociology.
Here to learn how to fix the internet without breaking it.
πIndia
L1 SOC Analyst
Computer Engineer
Linguaphile
Nerd
SOC Security Analyst @ Accenture
Cloud Solutions Architect | Microsoft Certified (AZ-104, AZ-305) | DevSecOps Engineer | SOC Analyst | Microsoft Beta Student Ambassador |
So how are you today?
|SOC Analyst @Thales
|Graphic Designer & Animator
|++I love listening and creating music
|YouTube: https://youtube.com/@chords6566?feature=shared
Award Winning Sound Designer | SOC Analyst (NSA, DIA, DoD) | Credits: Wrong Turn (2021) Halloween Ends (2022), The Exorcist: Believer (2024)
Senior SOC Analyst @ Kasperksy
SOC Analyst, Blacksmith | cat dad | OSINT enthusiast | Chicago, IL | Free Palestine π΅πΈ
InfoSec master's student and part-time SOC analyst. Inexperienced but interested in offensive security-related stuff.
SOC Analyst, Amateur- Astrophotographer and Astronomer, Flamefractal Artist
M1K3 | SOC Analyst | Cyber Nerd
SOC Analyst | Meme Conisseur | Space Enthusiast
SOC Analyst | Malware Analyst πΎ| Otaku π| Cat Lover πΎπ
Learning Cybersecurity on Tryhackme, trying to find my first job as a Cybersecurity Analyst SOC in France
https://tryhackme.com/r/p/EventualPanda
#Cybersecurity Trainer - Former #SOC Analyst
SOC Analyst
Threat Hunter
DFIR Specialist
Token Creation Service Provider
Senior Python Developer
Web Platform Engineer