Environment
Objective
Enable the collection of AMSI fileless_scriptload event data.
Resolution
Enable AMSI events in the Carbon Black EDR Console by toggling the collection of AMSI events per sensor group:
- On the navigation bar, click Sensors.
- Select the sensor group.
- In the Event Collection Settings section, select the checkbox for Fileless script loads.
- Click Save Group.
Additional Notes
- AMSI event capture is disabled by default.
- The fileless_scriptload event leverages the Anti-Malware Scanning Interface (AMSI)support that is available in Windows 10 RS2+ and Windows 2019+.
- To forward the information to the SIEM, check the box in the Event Forwarder > Events > Sensor > ingress.event.filelessscriptload.
- File-based scripts are logged locally.
- At this time this feature collects powershell.exe and not powershell_ise.exe