bykillvxk· 108 skills
通过识别 Base64 编码的启动器模式、默认 User-Agent、暂存 URL 结构、stager IOC 以及脚本块日志事件中已知的 Empire 模块签名,检测 Windows 事件日志中的 PowerShell Empire 框架工件。
$npx -y skills add killvxk/cybersecurity-skills-zh --skill analyzing-powershell-empire-artifactsInstalls into the current project.
Run `npx skills use "https://github.com/killvxk/cybersecurity-skills-zh" --skill "killvxk/cybersecurity-skills-zh/analyzing-powershell-empire-artifacts"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/killvxk/cybersecurity-skills-zh" that are relevant to the current task. Run `npx skills add "https://github.com/killvxk/cybersecurity-skills-zh"` and select the relevant skills, then follow their instructions.