// Investigation
Hunt console
Structured search across the normalised event store. Terms combine with AND; prefix a value with ! to negate it.
hunt.queryREADY
to run
Result profile
1
event matches
Severity
- Critical0
- High1
- Medium0
- Low0
- Info0
Applied filters
- process = powershell
- cmd = -enc
Matches
Newest first.
| Timestamp (UTC) | Severity | Event type | User | Source IP | Message |
|---|---|---|---|---|---|
| High | Process Execution | jsmith | 185.100.200.50 | Encoded PowerShell command block executed with hidden window and execution policy bypass |