IN PROGRESS
Technical summary
NEXUS PowerShell Abuse Detection Lab analyzes PowerShell commands and payloads against offensive patterns (AMSI bypass, download cradles, Mimikatz, reverse shells) with 4-layer deobfuscation and a 0–100 risk score. Each analysis generates synthesized EID 4104 forensic evidence, Sigma/SPL/KQL rules and a Blue Team verdict commented on the task — plus a MITRE ATT&CK catalog with 8 seed techniques, a Payload Studio to validate EDR/SIEM and a GPO script to enable Script-Block Logging.
Executed scope
- Plugin registration in
plugin.php:registerTab('nexus-powershell-abuse-lab', tab.php)with theterminalicon (Security category),registerDoc('nexus-powershell-abuse-lab', doc.md)and 16 API actions viaregisterApiAction(ps_prefix), withlegacy_slugs: ["powershell-abuse-lab"]inplugin.json. - Database (real DDL,
ps_install()withCREATE TABLE IF NOT EXISTS):ps_techniques(id, title, technique_id, tactic, severity, description, sample_command, deobfuscated, sigma_rule, splunk_spl, kql_query, analyst_notes, is_custom, created_at — editable technique catalog with embedded detection rules) andps_audit_history(task_id, title, raw_payload, deobfuscated_payload, risk_score, severity, techniques_detected JSON, eid_evidence JSON, analyst, created_at — audit trail with severity and created_at indexes). - Automatic seed: 8 base PowerShell abuse techniques (T1027 Obfuscation/EncodedCommand, T1059.001/T1105 Download Cradles, T1562.001 AMSI & ETW Bypass, T1003.001 Credential Dumping/Mimikatz, T1053.005/T1546.004 Persistence via Scheduled Tasks & WMI, T1071.001 TCP Reverse Shells, T1087/T1069 AD Discovery with PowerView/BloodHound, T1059.001 Execution Policy Bypass) — each with sample_command, deobfuscated version, Sigma YAML rule, ready-made SPL and KQL queries, and analyst notes.
- Extended MITRE catalog (
ps_get_extended_mitre_catalog): adds T1055.001 Process Injection via Reflection, T1047 WMI/CIM Execution, T1550.002 Pass-the-Hash/Kerberos Ticket Injection and more — a queryable, editable detection-rule bank (ps_technique_save/ps_technique_delete,is_customflag). - Forensic analysis (
ps_analyze): 4-layer deobfuscation — (1) Base64 UTF-16LE/ASCII from-EncodedCommand/-enc/raw strings, (2) tick-mark removal (backticksI\E\X), (3) string concatenation ('Dow'+'nload'), (4)-fformat operator ("{1}{0}" -f ...) — with a detected-layers report. - Risk heuristics: 8 weighted checks (CREDENTIAL_DUMP 45, AMSI_BYPASS 40, DOWNLOAD_CRADLE 35, REVERSE_SHELL 35, PERSISTENCE 25, DISCOVERY 20, OBFUSCATION_BASE64 20, EXECUTION_POLICY_BYPASS 15) applied to both the raw payload and the deobfuscated code — 0–100 score with CLEAN/LOW/MEDIUM/HIGH/CRITICAL severity.
- Synthesized EID 4104 evidence: every analysis builds the exact Script-Block Logging record (Provider
Microsoft-Windows-PowerShell, ChannelMicrosoft-Windows-PowerShell/Operational, ScriptBlockText with the deobfuscated code) for SIEM correlation validation. - Task integration: when a
task_idis provided, the plugin adds a comment with the full forensic verdict (risk, obfuscation layers, detected MITRE techniques, EID 4104 evidence in JSON and Blue Team recommendation — host blocking for CRITICAL). - Markdown report (
ps_export_report): structured verdict in 5 sections (EID 4688 input, EID 4104 deobfuscated code, MITRE techniques, JSON evidence and recommendations). - Payload Studio (
ps_generate_payload): generates benign payloads to validate EDR/SIEM in 5 variants —base64_encoded(UTF-16LE + flags),tick_marks,string_concat(fragmented IEX),format_operator(-f) anddownload_cradle_benign(points to the local API). - GPO activation (
ps_gpo_script): PowerShell script that enables Script-Block Logging (EID 4104), Module Logging (EID 4103), Transcription and grows the Operational log to 500MB viawevtutil. - Configuration in
ps_abuse_lab_settings(viaDB::getConfig):default_analyst,alert_on_critical,auto_deobfuscateandsiem_target(Splunk / Microsoft Sentinel). - Fast Responses:
fastr.jsonmanifest with/ps <script>(instant analysis with severity, score, layers and techniques —ps_analyze_fastr) and/powershell(technique catalog with severities —ps_techniques_fastr). - Intel Hub:
nx_intel_register_enricher('powershell-abuse-lab', ['_text'], 'ps_intel_enrich', 45)— texts with PowerShell patterns (Invoke-, IEX, DownloadString, AmsiUtils, sekurlsa, -enc) generate aninfo-severity artifact in the Intel Hub. - Interface (
tab.php): 4 KPIs (Registered Techniques, Audits Performed, Critical Threats, Ready Sigma/SPL/KQL rules) and 6 tabs — Analyzer & Forensic Evidence, Technique Catalog (editable), Payload Studio, GPO Activation, History (with clear) and Settings.
Stack and tools
- PHP 8 backend (no framework) + MySQL (
ps_techniques,ps_audit_history) - Advanced regex for layered deobfuscation and risk heuristics
- Alpine.js + Tailwind CSS (6 tabs, KPIs, catalog editor and rule viewer)
- Sigma YAML, Splunk SPL and Microsoft Sentinel KQL detection rules embedded per technique
- Internal Plugin API (PluginManager tabs/docs/actions +
fastr.json+ intel enricher) - NEXUS API Bearer token authentication on API calls
Operational tags
- PowerShell
- MITRE ATT&CK
- Blue Team
- Forensics
- Sigma
- SPL
- KQL
- AMSI
- Script-Block Logging
- Security
- NEXUS Plugin
Operational result
- Complete forensic analysis: 0–100 risk score, severity and Blue Team verdict for any PowerShell payload.
- 4-layer deobfuscation: Base64, tick marks, concatenation and
-f— the real code becomes evidence. - EID 4104 evidence: synthesized Script-Block Logging record for SIEM correlation validation.
- Ready-made rules: Sigma/SPL/KQL per technique, embedded in the catalog and exportable.
- Defense validation: Payload Studio generates benign variants to test EDR and SIEM.
- GPO hardening: ready script to enable Script-Block/Module Logging and Transcription on Windows.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS PowerShell Abuse Detection Lab analyzes PowerShell commands and payloads against offensive patterns (AMSI bypass, download cradles, Mimikatz, reverse shells) with 4-layer deobfuscation and a 0–100 risk score. Each analysis generates synthesized EID 4104 forensic evidence, Sigma/SPL/KQL rules and a Blue Team verdict commented on the task — plus a MITRE ATT&CK catalog with 8 seed techniques, a Payload Studio to validate EDR/SIEM and a GPO script to enable Script-Block Logging.
Architecture and organization
- PHP 8
- MySQL
- Alpine.js
- Tailwind CSS
- Regex
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.