Skip to content

Latest commit

 

History

History
20 lines (13 loc) · 912 Bytes

File metadata and controls

20 lines (13 loc) · 912 Bytes

TA-Microsoft-PowerShell

  • Author: Swisscom CSIRT, Swisscom (Schweiz) AG
  • Source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
  • Has index-time ops: false

Update History

0.2.0 - 2020-02-13

0.1.0 - 2019-03-01

  • Add initial PowerShell event log field extraction
  • Tested with PowerShell 5.1

Using this TA

Configuration: Install TA via GUI on all search heads, install via your preferred method (manual or Deployment Server) on forwarders running on Windows.