⌕
Showing 11 of 11 events
Cross-channel reference for PowerShell forensic analysis. Covers Microsoft-Windows-PowerShell/Operational (script block and module logging), the legacy Windows PowerShell log, and the separate PowerShellCore/Operational channel used by PowerShell 7 — a commonly missed gap when monitoring only the classic PowerShell log.
Curated highest-signal Sigma-style detection rules for PowerShell Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.
Convert to your SIEM: sigconverter.io