Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team project.
MIT License
805
stars
190
forks
source link
Provide process id and process exit code to loggers #107
Would it be possible to pass Invoke-Process $Process.Id and $Process.Exit code to loggers via Write-ExecutionLog?
The process id is specially helpful when correlating with EDR timelines to validate detections.
This is a feature request.
Would it be possible to pass Invoke-Process $Process.Id and $Process.Exit code to loggers via Write-ExecutionLog? The process id is specially helpful when correlating with EDR timelines to validate detections.
Thanks in advance!