From c4719bdba795fc08329c4e9dabea37a0781122a1 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com> Date: Thu, 17 Nov 2022 15:46:49 +0100 Subject: [PATCH] fix: add missing definition --- .../powershell_script/posh_ps_win_defender_exclusions_added.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml b/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml index 07b8ab10c..e51b3c716 100644 --- a/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml +++ b/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml @@ -17,6 +17,7 @@ tags: logsource: category: ps_script product: windows + definition: Script block logging must be enabled detection: selection_args_exc: ScriptBlockText|contains: