Detect and Decode Base64-Encoded PowerShell Commands - http
The query identifies Windows PowerShell executions using encoded commands, extracts and decodes Base64 payloads (including nested encodings), counts occurrences and unique hosts, and outputs decoded command content for analysis of potentially obfuscated activity.
CQL · Falcon Next-Gen SIEMCopy query
Loading query…Detect_and_Decode_Base64-Encoded_PowerShell_Commands-http.yml
CrowdStrike
Hunting
Endpoint
Insight
