You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I played with this a bit more; the two that I was going to build aren't as atomic as I thought they would be.
Thought they would indicate that the user had direct access to the terminal, but seems to also apply if they run a script without opening the terminal.
40961 - Microsoft-Windows-PowerShell%4Operational.evtx
Powershell console is starting - This is a sign of a user starting a powershell console for input
https://www.blackhat.com/docs/us-14/materials/us-14-Kazanciyan-Investigating-Powershell-Attacks-WP.pdf
(Assign to me if possible and I'll get to it when i have a spare 5!)
The text was updated successfully, but these errors were encountered: