Suspicious PowerShell
Detection and analysis of suspicious PowerShell execution on the Windows endpoint.

CASE STUDY / DETECTION ENGINEERING
Building a SIEM lab with Splunk & Atomic Red Team.
A hands-on Security Operations Center lab connecting Windows endpoint activity to centralized investigation, ATT&CK-aligned detections, and real-time alerting.
Explore the GitHub repository ↗01 / OBJECTIVE
The goal was to build a small SOC environment that could collect endpoint logs, surface suspicious activity, and connect individual events into meaningful attack sequences. The lab covers the path from telemetry collection through detection and investigation.
02 / LAB ARCHITECTURE
Controlled adversarial behavior on the Windows endpoint
Sysmon + Splunk Universal Forwarder
Splunk Enterprise, dashboards, and correlation searches
Both virtual machines run in VirtualBox. This diagram illustrates the lab setup; it is not a captured dashboard.
03 / IMPLEMENTATION
Set up Windows 10 as the target endpoint and Ubuntu Server as the host for Splunk Enterprise.
Deployed Sysmon with the SwiftOnSecurity configuration and installed Splunk Universal Forwarder. Verified log ingestion and search functionality.
Used Atomic Red Team to exercise attack techniques in the lab and map the resulting activity to the MITRE ATT&CK framework.
Created dashboards, alerts, SPL searches, and correlation logic for individual techniques and multi-stage activity.
04 / DETECTION SCENARIOS
Detection and analysis of suspicious PowerShell execution on the Windows endpoint.
Monitoring and alerting for repeated login attempts associated with brute-force activity.
Identification of registry-based boot or logon autostart persistence.
Correlation of brute-force activity with a subsequent successful login using a valid account.
Correlation of PowerShell activity with registry persistence to identify a multi-stage sequence.
05 / OUTCOMES
Scope: a controlled lab project. These outcomes describe the implementation; they do not establish production detection coverage or measured accuracy.
06 / TAKEAWAYS
The workflow brings three parts of detection engineering together: collecting useful endpoint telemetry, understanding the behavior behind an event, and correlating related activity. The multi-stage scenarios show why a sequence of events can provide more context than an isolated alert.