Forum Discussion

JKatzmandu's avatar
JKatzmandu
Brass Contributor
Nov 16, 2020

Finding base64 encoded commands

All,   I put together a query to look for base64-encoded strings on Command Lines where powershell has been executed. So I whipped up the following query: SecurityEvent | where TimeGenerated betw...

Resources