Defender-DeviceEvents › Event 9007001

Event ID 9007001 — PowerShell command executed

Provider
Defender-DeviceEvents
Channel
PowerShellCommand

Description

PowerShell command executed — PowerShell ScriptBlockLogging captures the same surface.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName
InitiatingProcessCommandLine

Detection Patterns #

References #