PowerShell Integration
in progress
Chris Bisnett
in progress
We've implemented the ability to collect PowerShell logs, but it is currently behind a feature flag so that we can control the rollout and monitor the data to identify cases were we can use Smart Filtering to reduce the amount of data being stored.
We're also working on some detection capabilities that will believe will allow us to separate PowerShell scripts that are part of the operating system from other scripts that need additional scrutiny to identify malicious activity.
James Mason | PMM @ Huntress
this quarter