Jul 03 2022 04:17 AM
I was going through the MITRE eval results for 2022.
One of the queries for script executions is documented as a DeviceEvent table search for ActionType "AmsiScriptContent". Looks like a very useful log source.
However, I was not able to replicate this query in my own environment. There is 0 results for "AmsiScriptContent" anywhere in the schema or online.
Would be grateful if anyone can confirm they are able to replicate this query or not.
References:
Jul 05 2022 05:28 AM
Jul 05 2022 05:31 AM
SolutionJul 05 2022 06:22 AM - edited Jul 05 2022 06:34 AM
Under which table? DeviceEvents? Update: You nailed it. It is indeed changed to ScriptContent ActionType under DeviceEvents Table.
It is not documented in the schema though...
Jul 05 2022 05:31 AM
Solution