add definition

This commit is contained in:
frack113
2021-09-22 08:40:08 +02:00
committed by GitHub
parent d884f774f9
commit 045e87058b
@@ -11,6 +11,7 @@ author: Max Altgelt
logsource:
product: windows
service: powershell
definition: Script block logging must be enabled
detection:
dump:
EventID: 4104