mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update ssa___windows_exchange_powershell_module_usage.yml
This commit is contained in:
@@ -38,7 +38,7 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map
|
||||
| into write_ssa_detected_events();'
|
||||
how_to_implement: To successfully implement this analytic, you will need to enable
|
||||
PowerShell Script Block Logging on some or all endpoints. Additional setup here
|
||||
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
|
||||
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. This will only work with Multiline event logs, not XML.
|
||||
known_false_positives: Administrators or power users may use this PowerShell commandlet
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps
|
||||
|
||||
Reference in New Issue
Block a user