Forum Discussion

mohammadnaser's avatar
mohammadnaser
Copper Contributor
Nov 22, 2022

Windows Defender Logs of PowerShell Commands

Hello,

 

We were trying to execute a PowerShell command that trying to bypass the defender, and we integrate the Microsoft Defender with Microsoft Sentinel Solution, so, we need to check the logs of that powershell command, for example, if a user execute a powershell command like 

Set-ExecutionPolicy -scop CurrentUser

The event log in Security Center and Sentinel Will display just "Set-ExecutionPolicy" without the options used in that command.

Is it normal behavior for log collection for Defender, or there is a custom rule need to be applied?

 

Thanks. 

No RepliesBe the first to reply

Resources