MDE - Host Advanced Hunting For Powershell Executions

This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature to hunt for host PowerShell executions.

Pack
MicrosoftDefenderAdvancedThreatProtection
Tasks
16

Inputs

Outputs

Commands used