mirror of
https://github.com/OTRF/OSSEM-DD
synced 2026-06-08 12:05:33 +00:00
f9f3b5699c
- updated log_source to PowerShell - added event samples (friendly view and xml)
name: PowerShell Event Logs description: None images: [] references: - text: Greater Visibility Through PowerShell Logging link: https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html - text: Investigating PowerShell Attacks - Slides link: https://www.defcon.org/images/defcon-22/dc-22-presentations/Kazanciyan-Hastings/DEFCON-22-Ryan-Kazanciyan-Matt-Hastings-Investigating-Powershell-Attacks.pdf - text: Investigation PowerShell Attacks - Paper link: https://www.blackhat.com/docs/us-14/materials/us-14-Kazanciyan-Investigating-Powershell-Attacks-WP.pdf