sysmon-modular
sysmon-modular copied to clipboard
Create include_powershell_profiles.xml
Added PowerShell profile paths for "T1546.013 Event Triggered Execution: PowerShell Profile" detection