Hi,
Thank you for the follow up.
I am not clear on what you are asking here - "Does the second query show up on the Locally on Endpoint ?"
on the endpoint in the access protection log, i get no errors and the correct entry.
2/2/2021 7:45:59 AM mfeesp(5920.1488) <SYSTEM> ApBl.AP.Activity: domain\user ran C:\Windows\System32\cmd.exe, which tried to access the file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, violating the rule "Monitor PowerShell Usage W10", and was blocked. For information about how to respond to this event, see KB85494.
Issue is, 1. i am not able to create report in epo for specified rule above as that rule does not show as a threat name.
2. the endpoint does not appear to be sending events to epo for this rule.
I tested with eicar also and the event for eicar did show in epo.
thoughts?