Attackers have been adopting PowerShell quickly in recent years. As such, it is important to provide logging around this powerful tool. A new detailed script-tracing feature lets you enable tracking and analysis of Windows PowerShell scripting use on a system. After you enable detailed script tracing, Windows PowerShell logs all script blocks to the Event Tracing for Windows (ETW) event log, Microsoft-Windows-PowerShell/Operational.
Number of occurrences in rules | Eventid | Event log | Event source or category |
|---|---|---|---|
1 | 4100 | Microsoft-Windows-PowerShell/Operational | PowerShell (Microsoft-Windows-PowerShell) |