On [insert date and time of incident], the Hyper Detect security solution detected a suspicious PowerShell execution on workstation [hostname or username]. While the decoded command appears to simply ...
Tested with PowerShell v5.1.19041.1645 on Windows 10 Enterprise OS (64-bit). Made for educational purposes. I hope it will help! This repository started to have known signatures and I don't have time ...