Jump to content

Recommended Posts

Posted

I wanted to share some resources about PowerShell logs for anyone unfamiliar with enabling Scriptblock logging.

Run>gpedit.msc. > User Configuration\Administrative Templates\Windows Components\Windows Powershell\Turn on Powershell Script Block Logging,Transcription

https://nsfocusglobal.com/Attack-and-Defense-Around-PowerShell-Event-Logging/#:~:text=1 EID 400: The engine status is changed,status is changed from Available to Stopped.

https://adamtheautomator.com/powershell-logging-2/
https://github.com/littl3field

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...