Detecting Suspicious PowerShell Activity
Learn how to identify suspicious PowerShell behavior using process relationships, command-line activity, encoded commands, and supporting telemetry.
A cybersecurity hobyist, detection engineer, stoic, and much more.
My goal is to provide valuable information that you can take and grow your own expertise. To share what I have learned from my personal experience as a detection engineer and cybersecurity enthusiast.
In this blog, I will break down topics (for the muggles), sharing ideas, discuss tools & malware, and provide educational content. Find this blog as a tool for yourself and to share with others.
Learn how to identify suspicious PowerShell behavior using process relationships, command-line activity, encoded commands, and supporting telemetry.
Learn the Incident Response Process using the SANS six-step methodology. This guide covers preparation, identification, containment, eradication, recovery, and lessons learned for effective cybersecurity incident response.
Practical cybersecurity knowledge—rooted in real-world investigation.
Explore detection engineering, malware behavior, network fundamentals, security tooling, and the systems quietly powering the digital world. No unnecessary jargon. Just clear explanations, useful techniques, and lessons learned from the field.
Turn raw telemetry into useful detections. Explore threat-hunting methods, query development, behavioral analytics, and lessons from working inside a modern SOC.
Break down how malicious software behaves—from initial execution and persistence to command-and-control traffic, indicators, and detection opportunities.
Understand what is happening behind the packets. Learn how DNS, SMTP, proxies, firewalls, authentication, and other foundational technologies actually work.
Build environments where you can safely experiment. Explore Security Onion, Linux, cloud labs, scripts, utilities, and hands-on cybersecurity projects.