Good morning,
First I want to say thanks again for all the help this group has been!
I may not be searching the group properly but, I'm trying to determine if and how I would monitor the Windows Powershell event logs under the Application and Service Logs on a Windows client.
I use Powershell pretty regularly on my laptop and I have the Wazuh client installed but I don't see any of the Powershell events when I look at the security events of my laptop's agent in the dashboard. So I assume I need to update both the ossec.conf on the manager and the ossec.conf on my laptop but I'm just guessing.
Since so much malware/ransomware uses Powershell covertly I would really love to monitor for odd Powershell usage and appreciate any guidance on how to set that up.
I apologize if this has been addressed in the past and I didn't find the article.
Thanks for your help!
Bill