Hey, excellent project absolutely wonderful and to have been continously maintained by a single dev is absolutely nuts. Can't wait for when the beta version gets released and whenever I get the time off my busy schedule I'll make a PR to help out.
So to the main deal I don't know yet if you have smth like this implemented already but having a cmd/powershell runtime deobfuscator would be a major upgrade for the EDR you can check this repos out on that.
https://github.com/KingKDot/Exorcism
https://github.com/KingKDot/Exorcism-PowershellEdition
Hey, excellent project absolutely wonderful and to have been continously maintained by a single dev is absolutely nuts. Can't wait for when the beta version gets released and whenever I get the time off my busy schedule I'll make a PR to help out.
So to the main deal I don't know yet if you have smth like this implemented already but having a cmd/powershell runtime deobfuscator would be a major upgrade for the EDR you can check this repos out on that.
https://github.com/KingKDot/Exorcism
https://github.com/KingKDot/Exorcism-PowershellEdition