Forum Discussion
mohammadnaser
Nov 22, 2022Copper Contributor
Windows Defender Logs of PowerShell Commands
Hello,
We were trying to execute a PowerShell command that trying to bypass the defender, and we integrate the Microsoft Defender with Microsoft Sentinel Solution, so, we need to check the logs of that powershell command, for example, if a user execute a powershell command like
Set-ExecutionPolicy -scop CurrentUser
The event log in Security Center and Sentinel Will display just "Set-ExecutionPolicy" without the options used in that command.
Is it normal behavior for log collection for Defender, or there is a custom rule need to be applied?
Thanks.
No RepliesBe the first to reply