Building a Detection Foundation: Part 3 - PowerShell and…
ID: b14ce876-a754-5eaf-bcc4-71a3e37bbb00
STIX ID: report--b14ce876-a754-5eaf-bcc4-71a3e37bbb00
Feed Name: TrustedSec blog
This article advocates enabling PowerShell native logging (Module Logging 4103, Script Block Logging 4104, and Transcription) to capture in-memory and obfuscated PowerShell execution, provides configuration steps for Group Policy, registry, and PowerShell 7, discusses log volume and retention considerations, and outlines detection opportunities and limitations compared with AMSI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
