CQL Hubby ByteRay
← All queries

Detect and Decode Base64-Encoded PowerShell Commands - http

The query identifies Windows PowerShell executions using encoded commands, extracts and decodes Base64 payloads (including nested encodings), counts occurrences and unique hosts, and outputs decoded command content for analysis of potentially obfuscated activity.

CQL · Falcon Next-Gen SIEMCopy query
Loading query…
Detect_and_Decode_Base64-Encoded_PowerShell_Commands-http.yml
CrowdStrike
Hunting
Endpoint
Insight

Want this running in your SIEM — with someone on call?

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team