# t3l3machus/PowerShell-Obfuscation-Bible

A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository are the result of personal research, including reading materials online and conducting trial-and-error attempts in labs and pentests.

Repository: https://github.com/t3l3machus/PowerShell-Obfuscation-Bible
Canonical: https://ross.abutalabs.com/products/powershell-obfuscation-bible
License: MIT
License Family: permissive
Topics: hacking, obfuscation, offensivesecurity, pentest, powershell, redteam
Last push: 2024-07-19T07:05:32+00:00

## Health v2 (maintenance only)
Score: 30/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 88
- inputs: {"age_days": 1240, "days_push": 775, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1204, forks 137 (observed 2026-08-28T04:03:58.745881+00:00)

## What it is
A curated educational reference of manual PowerShell script obfuscation techniques for bypassing signature-based antivirus detection, with examples and theory. It is a knowledge repository compiled from personal research, labs, and pentest experience.

## Use cases
- learn powershell obfuscation techniques
- bypass signature-based AV detection in pentests
- understand entropy in malware evasion
- study red team evasion methods
- find ways to de-chaff detected powershell scripts
- prepare for offensive security certifications

## When to choose
- you are a pentester or red teamer learning to manually obfuscate PowerShell payloads
- you want a reference of concrete obfuscation techniques with examples
- you are studying AV/EDR evasion for educational purposes

## When to avoid
- you need an automated obfuscation tool rather than a manual technique guide
- you are looking for defensive detection guidance rather than offensive techniques
- you need production software rather than a reference document

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, reverse-engineering, penetration-testing
- domain: security, penetration-testing, tutorials
- platform: windows, cross-platform
- tags: powershell, obfuscation, av-evasion, red-team, offensive-security, educational

## Member repositories
- t3l3machus/PowerShell-Obfuscation-Bible (main) score 30

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:58.745881+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:19:40.968716+00:00, confidence not recorded.
  - readme: https://github.com/t3l3machus/PowerShell-Obfuscation-Bible (fetched 2026-08-28T04:03:58.745881+00:00, sha 21af0d267366)
- Data as of 2026-08-30T08:39:29.467469+00:00.
