New
#1
Could Powershell events be the signs of remote unauthorized access?
Hi guys,
While checking out my Windows 7 Pro event viewer, I found about 20 warnings, related to two events under the "Windows Powershell" item on "Services and applications registries".
There are only 2 dates which the events refer to: october 3, and january 22.
I didn't even know what Powershell was and how to run it. But after checking online, I tried to launch the Powershell on my PC and after that I noticed that the Event Viewer was updated with a new "Powershell" warning event. So I guess that whenever Powershell is launched, the EventViewer register such action.
The odd thing though, is that I never ran the Powershell before. Could the october 3 and january 22 Powershell events be related to some remote unauthorized access? Or maybe some application installed on my PC needs to run Powershell instances for some reason?
Thanks!