Post cover image

August 22, 2026

Investigating a Suspicious PowerShell Alert with Wazuh and Sysmon

For my next SOC lab investigation, I wanted to look at a different type of alert: suspicious PowerShell activity.

By Larry Kaheiwong

4 min read