PowerShell Logging for the Blue Team
ID: 0eadba4d-02ce-5283-bf06-9902fea268d5
STIX ID: report--0eadba4d-02ce-5283-bf06-9902fea268d5
Feed Name: Black Hills Infosec Blog
This report explains how to improve detection of malicious PowerShell activity by upgrading to Windows Management Framework/PowerShell 5.0 and enabling logging features: module logging (Event ID 4103), script block logging (Event ID 4104, with 4105/4106 optional), and full transcription. It covers installing the Administrative Templates for Group Policy, where the PowerShell Operational logs appear, practical considerations (e.g., WMF and .NET dependencies on Windows 7), and recommends enabling script block logging and centralizing logs to support hunting and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
