spicosolutions / thepeoplessiem

Patronus Support Portal
0 stars 0 forks source link

SSRG429 - PowerShell ShellCode #29

Closed TomDiTullio closed 2 years ago

TomDiTullio commented 2 years ago

Source is source="WinEventLog:Microsoft-Windows-PowerShell/Operational" when it needs to be source="WinEventLog:Microsoft-Windows-Sysmon/Operational" OR source="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"