config: thor - powershell classic
This commit is contained in:
@@ -176,6 +176,11 @@ logsources:
|
||||
service: powershell
|
||||
sources:
|
||||
- "WinEventLog:Microsoft-Windows-PowerShell/Operational"
|
||||
windows-classicpowershell:
|
||||
product: windows
|
||||
service: powershell-classic
|
||||
sources:
|
||||
- "WinEventLog:Windows PowerShell"
|
||||
windows-taskscheduler:
|
||||
product: windows
|
||||
service: taskscheduler
|
||||
|
||||
Reference in New Issue
Block a user