Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Finding PowerShell activity with LEM

$
0
0

We found a couple of ways to do this:

Using Sysmon events and setting a rule to look for powershell

Or enabling powershell script block logging and forwarding those events.With powershell you can look for the ToolAlias and those are all your PS events.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>