Solved
Forum Discussion
netcat
Silver II
2 months agoWell, in this case you should narrow down the search, next step:
(EventCode=4103 OR EventCode=4104) powershell .ps1
Narrow down further, removing non relevant scripts:
(EventCode=4103 OR EventCode=4104) powershell .ps1 NOT sample.ps1