You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This Splunk dashboard detects PowerShell EncodedCommand use (T1059.001) by flagging base64 blobs over 500 bytes, with 1-second timeline, host stats, and event counts, based on index=main data and installable as a JSON file or app on Splunk Cloud or 9.x.