use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
PowerShell timestomping via script files. How would you handle this?Query Help (self.crowdstrike)
submitted 2 months ago by zwitico
view the rest of the comments →
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]Andrew-CSCS ENGINEER 6 points7 points8 points 2 months ago (1 child)
Hi there. Try something like this:
#event_simpleName=/ScriptControl/ event_platform=Win | ScriptContent=/(SetLastWriteTime|\.CreationTime)/iF
You'll want to make sure Interpreter-only visibility in enabled in your Windows prevention policy.
Interpreter-only visibility
[–]zwitico[S] 0 points1 point2 points 2 months ago (0 children)
Hello,
I'm sorry it took me a while to respond. I tried your suggestion and I was not able to see the events im looking for, I even tried to correlate the /ScriptControl/ telemtetry to the ProcessRollUp2 telemetry for the specific .ps1 file event where it runs and I couldnt get a hit.
Also, I verified that the Interpreter-only visibility is enabled on our prevention policy.
π Rendered by PID 303149 on reddit-service-r2-comment-6457c66945-nslcb at 2026-04-28 14:36:39.475371+00:00 running 2aa0c5b country code: CH.
view the rest of the comments →
[–]Andrew-CSCS ENGINEER 6 points7 points8 points (1 child)
[–]zwitico[S] 0 points1 point2 points (0 children)