Cover image for project: NEXUS PowerShell Abuse Detection Lab IN PROGRESS

Technical summary

NEXUS PowerShell Abuse Detection Lab analyzes PowerShell commands and payloads against offensive patterns (AMSI bypass, download cradles, Mimikatz, reverse shells) with 4-layer deobfuscation and a 0–100 risk score. Each analysis generates synthesized EID 4104 forensic evidence, Sigma/SPL/KQL rules and a Blue Team verdict commented on the task — plus a MITRE ATT&CK catalog with 8 seed techniques, a Payload Studio to validate EDR/SIEM and a GPO script to enable Script-Block Logging.

Executed scope

  • Plugin registration in plugin.php: registerTab('nexus-powershell-abuse-lab', tab.php) with the terminal icon (Security category), registerDoc('nexus-powershell-abuse-lab', doc.md) and 16 API actions via registerApiAction (ps_ prefix), with legacy_slugs: ["powershell-abuse-lab"] in plugin.json.
  • Database (real DDL, ps_install() with CREATE TABLE IF NOT EXISTS): ps_techniques (id, title, technique_id, tactic, severity, description, sample_command, deobfuscated, sigma_rule, splunk_spl, kql_query, analyst_notes, is_custom, created_at — editable technique catalog with embedded detection rules) and ps_audit_history (task_id, title, raw_payload, deobfuscated_payload, risk_score, severity, techniques_detected JSON, eid_evidence JSON, analyst, created_at — audit trail with severity and created_at indexes).
  • Automatic seed: 8 base PowerShell abuse techniques (T1027 Obfuscation/EncodedCommand, T1059.001/T1105 Download Cradles, T1562.001 AMSI & ETW Bypass, T1003.001 Credential Dumping/Mimikatz, T1053.005/T1546.004 Persistence via Scheduled Tasks & WMI, T1071.001 TCP Reverse Shells, T1087/T1069 AD Discovery with PowerView/BloodHound, T1059.001 Execution Policy Bypass) — each with sample_command, deobfuscated version, Sigma YAML rule, ready-made SPL and KQL queries, and analyst notes.
  • Extended MITRE catalog (ps_get_extended_mitre_catalog): adds T1055.001 Process Injection via Reflection, T1047 WMI/CIM Execution, T1550.002 Pass-the-Hash/Kerberos Ticket Injection and more — a queryable, editable detection-rule bank (ps_technique_save/ps_technique_delete, is_custom flag).
  • Forensic analysis (ps_analyze): 4-layer deobfuscation — (1) Base64 UTF-16LE/ASCII from -EncodedCommand/-enc/raw strings, (2) tick-mark removal (backticks I\E\X), (3) string concatenation ('Dow'+'nload'), (4) -f format operator ("{1}{0}" -f ...) — with a detected-layers report.
  • Risk heuristics: 8 weighted checks (CREDENTIAL_DUMP 45, AMSI_BYPASS 40, DOWNLOAD_CRADLE 35, REVERSE_SHELL 35, PERSISTENCE 25, DISCOVERY 20, OBFUSCATION_BASE64 20, EXECUTION_POLICY_BYPASS 15) applied to both the raw payload and the deobfuscated code — 0–100 score with CLEAN/LOW/MEDIUM/HIGH/CRITICAL severity.
  • Synthesized EID 4104 evidence: every analysis builds the exact Script-Block Logging record (Provider Microsoft-Windows-PowerShell, Channel Microsoft-Windows-PowerShell/Operational, ScriptBlockText with the deobfuscated code) for SIEM correlation validation.
  • Task integration: when a task_id is provided, the plugin adds a comment with the full forensic verdict (risk, obfuscation layers, detected MITRE techniques, EID 4104 evidence in JSON and Blue Team recommendation — host blocking for CRITICAL).
  • Markdown report (ps_export_report): structured verdict in 5 sections (EID 4688 input, EID 4104 deobfuscated code, MITRE techniques, JSON evidence and recommendations).
  • Payload Studio (ps_generate_payload): generates benign payloads to validate EDR/SIEM in 5 variants — base64_encoded (UTF-16LE + flags), tick_marks, string_concat (fragmented IEX), format_operator (-f) and download_cradle_benign (points to the local API).
  • GPO activation (ps_gpo_script): PowerShell script that enables Script-Block Logging (EID 4104), Module Logging (EID 4103), Transcription and grows the Operational log to 500MB via wevtutil.
  • Configuration in ps_abuse_lab_settings (via DB::getConfig): default_analyst, alert_on_critical, auto_deobfuscate and siem_target (Splunk / Microsoft Sentinel).
  • Fast Responses: fastr.json manifest with /ps <script> (instant analysis with severity, score, layers and techniques — ps_analyze_fastr) and /powershell (technique catalog with severities — ps_techniques_fastr).
  • Intel Hub: nx_intel_register_enricher('powershell-abuse-lab', ['_text'], 'ps_intel_enrich', 45) — texts with PowerShell patterns (Invoke-, IEX, DownloadString, AmsiUtils, sekurlsa, -enc) generate an info-severity artifact in the Intel Hub.
  • Interface (tab.php): 4 KPIs (Registered Techniques, Audits Performed, Critical Threats, Ready Sigma/SPL/KQL rules) and 6 tabs — Analyzer & Forensic Evidence, Technique Catalog (editable), Payload Studio, GPO Activation, History (with clear) and Settings.

Stack and tools

  • PHP 8 backend (no framework) + MySQL (ps_techniques, ps_audit_history)
  • Advanced regex for layered deobfuscation and risk heuristics
  • Alpine.js + Tailwind CSS (6 tabs, KPIs, catalog editor and rule viewer)
  • Sigma YAML, Splunk SPL and Microsoft Sentinel KQL detection rules embedded per technique
  • Internal Plugin API (PluginManager tabs/docs/actions + fastr.json + intel enricher)
  • NEXUS API Bearer token authentication on API calls

Operational tags

  • PowerShell
  • MITRE ATT&CK
  • Blue Team
  • Forensics
  • Sigma
  • SPL
  • KQL
  • AMSI
  • Script-Block Logging
  • Security
  • NEXUS Plugin

Operational result

  • Complete forensic analysis: 0–100 risk score, severity and Blue Team verdict for any PowerShell payload.
  • 4-layer deobfuscation: Base64, tick marks, concatenation and -f — the real code becomes evidence.
  • EID 4104 evidence: synthesized Script-Block Logging record for SIEM correlation validation.
  • Ready-made rules: Sigma/SPL/KQL per technique, embedded in the catalog and exportable.
  • Defense validation: Payload Studio generates benign variants to test EDR and SIEM.
  • GPO hardening: ready script to enable Script-Block/Module Logging and Transcription on Windows.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS PowerShell Abuse Detection Lab analyzes PowerShell commands and payloads against offensive patterns (AMSI bypass, download cradles, Mimikatz, reverse shells) with 4-layer deobfuscation and a 0–100 risk score. Each analysis generates synthesized EID 4104 forensic evidence, Sigma/SPL/KQL rules and a Blue Team verdict commented on the task — plus a MITRE ATT&CK catalog with 8 seed techniques, a Payload Studio to validate EDR/SIEM and a GPO script to enable Script-Block Logging.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.