{"adoption": {"forks": 137, "observed_at": "2026-08-28T04:03:58.745881+00:00", "stars": 1204}, "canonical_url": "https://ross.abutalabs.com/products/powershell-obfuscation-bible", "card": {"archived": false, "artifact_type": "learning-resource", "description": "A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository are the result of personal research, including reading materials online and conducting trial-and-error attempts in labs and pentests.", "domain": ["security", "penetration-testing", "tutorials"], "enriched": true, "function": ["security", "reverse-engineering", "penetration-testing"], "health_score": 20, "homepage": null, "language": null, "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["t3l3machus/PowerShell-Obfuscation-Bible"], "name": "t3l3machus/PowerShell-Obfuscation-Bible", "platform": ["windows", "cross-platform"], "pushed_at": "2024-07-19T07:05:32+00:00", "repo": "t3l3machus/PowerShell-Obfuscation-Bible", "stars": 1204, "tags": ["powershell", "obfuscation", "av-evasion", "red-team", "offensive-security", "educational"], "topics": ["hacking", "obfuscation", "offensivesecurity", "pentest", "powershell", "redteam"], "urls": [], "use_cases": ["learn powershell obfuscation techniques", "bypass signature-based AV detection in pentests", "understand entropy in malware evasion", "study red team evasion methods", "find ways to de-chaff detected powershell scripts", "prepare for offensive security certifications"], "what_it_is": "A curated educational reference of manual PowerShell script obfuscation techniques for bypassing signature-based antivirus detection, with examples and theory. It is a knowledge repository compiled from personal research, labs, and pentest experience.", "when_to_avoid": ["you need an automated obfuscation tool rather than a manual technique guide", "you are looking for defensive detection guidance rather than offensive techniques", "you need production software rather than a reference document"], "when_to_choose": ["you are a pentester or red teamer learning to manually obfuscate PowerShell payloads", "you want a reference of concrete obfuscation techniques with examples", "you are studying AV/EDR evasion for educational purposes"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/powershell-obfuscation-bible", "repo": "t3l3machus/PowerShell-Obfuscation-Bible", "role": "main", "score": 30}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:58.745881+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:19:40.968716+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "21af0d267366ab9afe8c57bd62b067a1270956b52bc02bd39c303e3c2fff5903", "fetched_at": "2026-08-28T04:03:58.745881+00:00", "kind": "readme", "missing": false, "url": "https://github.com/t3l3machus/PowerShell-Obfuscation-Bible"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 88, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1240, "days_push": 775, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 30, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}