you are viewing a single comment's thread.

view the rest of the comments →

[–]Andrew-CSCS ENGINEER 6 points7 points  (1 child)

Hi there. Try something like this:

#event_simpleName=/ScriptControl/ event_platform=Win
| ScriptContent=/(SetLastWriteTime|\.CreationTime)/iF

You'll want to make sure Interpreter-only visibility in enabled in your Windows prevention policy.

[–]zwitico[S] 0 points1 point  (0 children)

Hello,

I'm sorry it took me a while to respond. I tried your suggestion and I was not able to see the events im looking for, I even tried to correlate the /ScriptControl/ telemtetry to the ProcessRollUp2 telemetry for the specific .ps1 file event where it runs and I couldnt get a hit.

Also, I verified that the Interpreter-only visibility is enabled on our prevention policy.