diff --git a/evtx/Maps/PowerShellCore-Operational_PowerShellCore_4104.map b/evtx/Maps/PowerShellCore-Operational_PowerShellCore_4104.map new file mode 100644 index 0000000..11a3557 --- /dev/null +++ b/evtx/Maps/PowerShellCore-Operational_PowerShellCore_4104.map @@ -0,0 +1,50 @@ +Author: Andrew Rathbun +Description: Contains contents of scripts run +EventId: 4104 +Channel: "PowerShellCore/Operational" +Provider: PowerShellCore +Maps: + - + Property: PayloadData1 + PropertyValue: "Path: %Path%" + Values: + - + Name: Path + Value: "/Event/EventData/Data[@Name=\"Path\"]" + - + Property: PayloadData2 + PropertyValue: "ScriptBlockText: %ScriptBlockText%" + Values: + - + Name: ScriptBlockText + Value: "/Event/EventData/Data[@Name=\"ScriptBlockText\"]" + +# Documentation: +# Very similar to PowerShell:4104 events, but for PowerShellCore +# +# Example Event Data: +# +# +# +# 4104 +# 1 +# 3 +# 2 +# 15 +# 0x0 +# +# 1484 +# +# +# PowerShellCore/Operational +# HOSTNAME +# +# +# +# 1 +# 7 +# , #requires -version 3.0, try { Microsoft.PowerShell.Core\Set-StrictMode +# c79abe83-17c9-4e04-9de2-fbbd12321d38 +# +# +#