Andrew Leer · @leean00
1 followers · 14 posts · Server discuss.systems
Dan :dumpster_fire: · @4n68r
141 followers · 90 posts · Server infosec.exchange

Got 7 and not seeing event logs in your triage? N.B. for PowerShell 7: Windows PowerShell logs events to "Microsoft-Windows-PowerShell/Operational"), but PowerShell 7 now logs events to "PowerShellCore/Operational." Detailed (e.g., Script Block) logging is NOT enabled by default.

PowerShell 7 includes Group Policy templates and an installation script in $PSHOME. Specifically, you can use the "RegisterManifest.ps1" and "InstallPSCorePolicyDefinitions.ps1" scripts in the PS7 installation directory to enable logging.

Also, ISE doesn't support PS7 :( --> but there is an official Visual Studio Code extension that does, and it even has an "ISE Mode."

H/T Nasreddine Bencherchali ( @nas_bench@twitter.com ): twitter.com/nas_bench/status/1

I also consulted learn.microsoft.com/en-us/powe

#powershell #PowerShell7 #dfir #eventlogs #logging #artifacts

Last updated 2 years ago