مسیرش در Group Policy:
Administrative Templates
> Windows Components
> Windows PowerShell
> Turn on PowerShell Script Block Logging
این گزینه رو روی Enabled بذارید. ✅
بعد از فعالسازی، Event ID 4104 داخل این مسیر ثبت میشه:
Applications and Services Logs
> Microsoft
> Windows
> PowerShell
> Operational
🔴 "4104" به ما کمک میکنه بفهمیم داخل PowerShell چه Script یا Commandای اجرا شده.
البته برای تحلیل کاملتر، بهتره در کنار اون "4103" و "4688" رو هم بررسی کنیم.
@Socroot