logo

Hidden in Plain Sight: PowerShell Visibility Most Defender XDR Analysts Miss

ID: 9d577c1c-8291-5391-93b3-250207c8c2bc

STIX ID: report--9d577c1c-8291-5391-93b3-250207c8c2bc

Feed Name: Detect FYI

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Bi Yue Xu

...
...

This blog explains how to improve PowerShell visibility in Microsoft Defender XDR by querying DeviceEvents for PowerShellCommand telemetry to reveal commands executed inside .ps1 scripts; it provides sample KQL queries and hunting indicators (download functions, IEX/EncodedCommand, credential-dumping references, memory-injection APIs) to help investigators and threat hunters detect suspicious PowerShell activity when the script file is not available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.