September 27, 2026
Building Check-SuspiciousActivity: A Read-Only Windows Security Scanner in PowerShell
Building a read-only Windows security scanner in PowerShell with MITRE ATT&CK and risk scoring.
By Huseyn Hasanov
3 min read
Introduction
I built Check-SuspiciousActivity as a read-only Windows security diagnostic scanner written in PowerShell.
The goal was not to replace an antivirus or EDR solution. Instead, the scanner is designed to collect security-relevant information from a Windows system, identify suspicious indicators, organize the findings, and provide evidence that can be reviewed manually.
The project is available on GitHub:
https://github.com/hsynaze/Check-SuspiciousActivity
Why I Built It
Windows systems expose a large amount of information that can be useful during a security investigation: running processes, persistence mechanisms, scheduled tasks, services, WMI subscriptions, network connections, firewall rules, Defender configuration, event logs, browser extensions, and more.
I wanted to bring these checks together into one diagnostic tool while keeping an important constraint:
The scanner must remain read-only.
It should collect and analyze information without modifying the system or attempting to remove suspected malware.
What the Scanner Checks
Check-SuspiciousActivity currently examines multiple areas of a Windows system, including:
- Running processes and executable signatures
-
- SHA-256 hashes of relevant files
-
- Registry persistence mechanisms
-
- Startup folders
-
- Scheduled tasks
-
- Windows services
-
- WMI event subscriptions
-
- Active network connections
-
- Listening ports
-
- Windows Firewall inbound rules
-
- Hosts file configuration
-
- Proxy settings
-
- DNS configuration
-
- Browser extensions
-
- Local administrator accounts
-
- Windows Defender status and preferences
-
- Windows Event Logs
-
- Suspicious PowerShell command-line patterns
-
- Recently modified system files
-
- Drivers
-
- Volume Shadow Copy information
The scanner also maps relevant findings to MITRE ATT&CK techniques when appropriate.
Risk Scoring
A security scanner should not treat every unusual configuration as malware.
For that reason, the project uses a risk-scoring model that combines different types of evidence.
The scanner distinguishes between confirmed indicators, heuristic indicators, and contextual signals.
This is important because a single unusual file, hidden scheduled task, unsigned executable, or suspicious PowerShell string does not automatically prove that a system is compromised.
The goal is to provide investigation priorities rather than automatically declare a system infected.
IOC Generation
The scanner generates investigation data that can be useful during incident response.
Relevant findings can include:
- File paths
-
- Process information
-
- Service information
-
- Scheduled task information
-
- Network indicators
-
- SHA-256 hashes
-
- Other structured indicators
IOC output is deduplicated so that repeated observations do not unnecessarily produce duplicate indicators.
Keeping the Scanner Read-Only
One of the main design requirements was that the scanner should not perform remediation.
It does not:
- Remove files
-
- Quarantine files
-
- Terminate processes
-
- Modify registry settings
-
- Modify services
-
- Disable security controls
-
- Change firewall configuration
-
- Perform malware cleanup
The scanner is intended for diagnostics and investigation. Any remediation decision should be made separately after reviewing the collected evidence.
Quality Gates and Validation
I added internal Quality Gates to verify the integrity of the scan and generated reports.
The validation covers areas such as:
- Read-only behavior
-
- Source coverage
-
- Finding deduplication
-
- IOC deduplication
-
- Scanner self-exclusion
-
- Risk-score consistency
-
- JSON round-trip validation
-
- HTML structure
-
- HTML escaping
-
- Required report fields
-
- Parser validation
Version 2.0.0 was runtime-tested on Windows 11 Home using Windows PowerShell 5.1.26100.9549 with administrator privileges.
The runtime validation completed with:
OverallQualityStatus = PASS
RealScanErrors = 0
ReadOnlyStatus = PASS
CoverageStatus = PASS
DuplicateFindingStatus = PASS
DuplicateIOCStatus = PASS
DeduplicationStatus = PASS
SelfExclusionStatus = PASS
RiskScoreConsistencyStatus = PASS
IocJsonStatus = PASS
JsonRoundTripStatus = PASS
HtmlStructureStatus = PASS
HtmlEscapingStatus = PASS
False Positives and Heuristic Detection
During testing, VirusTotal produced several heuristic and Sigma-rule detections related to suspicious PowerShell patterns.
This was an important observation because the scanner itself contains patterns used to identify suspicious PowerShell behavior.
A defensive scanner can therefore contain strings that resemble malicious commands because it needs to recognize those patterns during analysis.
These detections were treated as investigation signals rather than automatic proof that the scanner was malicious.
This also reinforced one of the project's design principles: security findings should be evaluated in context.
Limitations
Check-SuspiciousActivity is a diagnostic scanner, not a replacement for an antivirus, EDR, SIEM, or professional incident-response process.
A finding can be legitimate system activity, a security tool, an administrative configuration, or an actual threat.
The scanner therefore provides evidence and indicators for further investigation rather than guaranteeing a definitive malware verdict.
PowerShell 5.1 is currently runtime-validated. PowerShell 7 has not yet been runtime-validated.
What I Learned
Building the scanner showed me that detecting suspicious behavior is not simply a matter of collecting a list of keywords.
Context matters.
The same PowerShell command, scheduled task, service, network connection, or unsigned executable can have very different meanings depending on its location, signer, parent process, configuration, and surrounding evidence.
I also learned that a security tool needs validation of its own behavior. Read-only guarantees, source-status checks, deduplication, report validation, and self-exclusion are important parts of the scanner itself.
Future Improvements
Future versions will focus on improving detection quality, reducing false positives, expanding Windows security coverage, improving contextual classification, and continuing compatibility testing.
The current public release is v2.0.0.
Conclusion
Check-SuspiciousActivity is my attempt to build a practical, transparent, and read-only Windows security diagnostic tool in PowerShell.
The project is open source and available on GitHub:
https://github.com/hsynaze/Check-SuspiciousActivity
Version 2.0.0 is the first public release.