Title
#windows
b

binu

02/13/2019, 12:25 PM
any configuration available for powershell_events enable via config i am using below one --windows_event_channels=Microsoft-Windows-PowerShell/Operational
manu

manu

02/14/2019, 6:53 AM
This table uses a feature called script block logging.
table_name("powershell_events")
description("Powershell script blocks reconstructed to their full script content, this table requires script block logging to be enabled.")
https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html once u enable these, u should be able to see these in your table output.