logo

Building a Detection Foundation: Part 3 - PowerShell and…

ID: b14ce876-a754-5eaf-bcc4-71a3e37bbb00

STIX ID: report--b14ce876-a754-5eaf-bcc4-71a3e37bbb00

Feed Name: TrustedSec blog

Date Published: 2026-03-10

Date Updated: 2026-05-01

...
...

This article advocates enabling PowerShell native logging (Module Logging 4103, Script Block Logging 4104, and Transcription) to capture in-memory and obfuscated PowerShell execution, provides configuration steps for Group Policy, registry, and PowerShell 7, discusses log volume and retention considerations, and outlines detection opportunities and limitations compared with AMSI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.