Suspicious JScript staging comment
Description
Microsoft has observed attackers who have gained entry to an environment via the Log4J vulnerability utilizing identifiable strings in PowerShell commands.
Query · kql
DeviceProcessEvents | where FileName =~ "powershell.exe" | where ProcessCommandLine has "VMBlastSG"