drop 4688 or sysmon evtx csv · wscript/cscript patterns · deleted scripts · obfuscation flags · child process analysis · export csv · runs locally
security 4688 · sysmon event 1 · mftrcsv for script file existence
drop 4688 or sysmon evtx csv · optional mft csv for deleted script detection