From 78c1d290c57ea9b126c67cd8d5632debc2f7263a Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 13 Oct 2022 15:10:26 -0600 Subject: [PATCH] Update ssa___windows_exchange_powershell_module_usage.yml --- .../endpoint/ssa___windows_exchange_powershell_module_usage.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml b/detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml index de57c7e320..198092fb25 100644 --- a/detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml +++ b/detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml @@ -38,7 +38,7 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map | into write_ssa_detected_events();' how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here - https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. + https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. This will only work with Multiline event logs, not XML. known_false_positives: Administrators or power users may use this PowerShell commandlet references: - https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps