PowerShell Suspicion: AMSI Bypass / PSv2 Downgrade / Single Host
Playbook applied when a PowerShell-sourced download cradle, AMSI bypass attempt, or PSv2 downgrade alert fires on a single host — in scenarios where no active C2 or lateral movement evidence has yet been found — for triage, controlled containment, and structural improvement.
Prepare
6 steps- Logging baseline verification
Verify that Script Block Logging (EID 4104) and Module Logging (EID 4103) are enabled via GPO and that the `Microsoft-Windows-PowerShell/Operational` log is forwarded to SIEM
- Sysmon coverage check
Verify that the EID 1 (ProcessCreate), EID 3 (NetworkConnect), EID 13 (RegistrySet) policy is running and that logs are included in centralized collection
- Triage account permission verification
Verify that the account used for response has read permission for `Microsoft-Windows-PowerShell/Operational`, `Windows PowerShell.evtx`, and Sysmon logs
- Forensics kit readiness
Verify that WinPMem or EDR live response memory dump capacity and CyberChef and PSDecode tools are accessible
- IR communication channel
Confirm that the SOC L1 → IR Lead → System owner → CISO escalation chain and the IR ticket/channel address are open
- Transcript destination share
Verify that PowerShell transcription logs are directed to a non-writable network share; if the destination is a local directory, the attacker can delete them