Forum Discussion
Hamza_Bilal
Jul 03, 2022Copper Contributor
AmsiScriptContent not under DeviceEvents table? MITRE Eval 2022
I was going through the MITRE eval results for 2022. One of the queries for script executions is documented as a DeviceEvent table search for ActionType "AmsiScriptContent". Looks like a very use...
- Jul 05, 2022Scratch that. The ActionType is now just 'ScriptContent'
jbmartin6
Jul 05, 2022Iron Contributor
I also get 0 results. Perhaps this event only registers when AMSI tags something
- jbmartin6Jul 05, 2022Iron ContributorScratch that. The ActionType is now just 'ScriptContent'
- Hamza_BilalJul 05, 2022Copper Contributor
Under which table? DeviceEvents? Update: You nailed it. It is indeed changed to ScriptContent ActionType under DeviceEvents Table.
It is not documented in the schema though...