* DumpCount
* DumpFolder
* DumpType:
0. Custom Dump
1. Mini Dump
2. Full Dump (Process)
![](wer_configuration.png)
---
## Powershell script logging
* Attackers use PowerShell extensively!
* Script block logging provides visibility into PowerShell activities.
```sh
New-Item -Path "HKLM:\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Force
Set-ItemProperty -Path "HKLM:\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Name "EnableScriptBlockLogging" -Value 1 -Force
```
---
## Powershell script logging
* Use Group Policy to enable it everywhere
---
## Powershell script logging
* Logging powershell gives a unique view at of attacker activities.