Hidden in Plain Sight: PowerShell Visibility Most Defender XDR Analysts Miss
ID: 9d577c1c-8291-5391-93b3-250207c8c2bc
STIX ID: report--9d577c1c-8291-5391-93b3-250207c8c2bc
Feed Name: Detect FYI
This blog explains how to improve PowerShell visibility in Microsoft Defender XDR by querying DeviceEvents for PowerShellCommand telemetry to reveal commands executed inside .ps1 scripts; it provides sample KQL queries and hunting indicators (download functions, IEX/EncodedCommand, credential-dumping references, memory-injection APIs) to help investigators and threat hunters detect suspicious PowerShell activity when the script file is not available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
