PowerShell/WinRM Operational
Console_History.txt / PsTranscripting:
# location:
%UserProfile%\AppData\Roaming\Microsoft\Windows\PowerShell\PsReadLinePowerShellCore-Operational.evtx (PSv6,7) PowerShell-Operational.evtx (PSv5)
EID
Quick Wins:
Downgrade attacks
WinRM/Operational.evtx
EID
Last updated