diff --git a/artifacts/definitions/Windows/System/PowerShell.yaml b/artifacts/definitions/Windows/System/PowerShell.yaml index d4bf41f04d6..2e00436ac39 100644 --- a/artifacts/definitions/Windows/System/PowerShell.yaml +++ b/artifacts/definitions/Windows/System/PowerShell.yaml @@ -54,7 +54,8 @@ sources: if(condition=len(list=Stderr) >= SizeLimit, then=upload(accessor="data", file=Stderr, - name="Stderr" + str(str=count()))) AS StderrUpload + name="Stderr" + str(str=count()))) AS StderrUpload, + * FROM execve(argv=[PowerShellExe, "-ExecutionPolicy", "Unrestricted", "-encodedCommand", base64encode(string=utf16_encode(string=Command))