EricZimmerman/evtx

Powershell map to build for later

randomaccess3 opened this issue · 2 comments

40961 - Microsoft-Windows-PowerShell%4Operational.evtx

Powershell console is starting - This is a sign of a user starting a powershell console for input

https://www.blackhat.com/docs/us-14/materials/us-14-Kazanciyan-Investigating-Powershell-Attacks-WP.pdf

(Assign to me if possible and I'll get to it when i have a spare 5!)

assigned! =)

I played with this a bit more; the two that I was going to build aren't as atomic as I thought they would be.
Thought they would indicate that the user had direct access to the terminal, but seems to also apply if they run a script without opening the terminal.