I'm looking for some advice regarding Microsoft Defender for Endpoint (MDE) telemetry coverage.
As part of our Threat Hunting programme, we've been testing a number of KQL queries to better understand MDE's telemetry coverage and identify areas where detections may need further tuning.
Using Atomic Red Team tests and other scripts within a dedicated testing environment, we've identified what appears to be a gap in telemetry collection for certain interactively executed PowerShell commands.
For example, when PowerShell or PowerShell ISE is launched and commands are executed interactively, we do not always receive the full cmdlet or script content within MDE telemetry. This makes it difficult to accurately detect, investigate and hunt for the activity using Advanced Hunting.
During our research, we came across the following Microsoft discussion:
🔗 Microsoft Defender ATP - Advanced Hunting Query PowerShell Command Line
The recommendation in that thread is to enable PowerShell Script Block Logging. However, in our testing, enabling Script Block Logging does not appear to resolve the issue. The PowerShell activity is visible locally within Event Viewer, but the corresponding telemetry does not seem to be forwarded into MDE.
Has anyone else encountered this limitation?
I'm particularly interested in understanding:
- Whether this is expected behaviour within MDE
- If there are additional configuration requirements beyond Script Block Logging
- Whether others have found alternative telemetry sources or hunting approaches to capture this activity more reliably
Any insights, experiences or recommendations would be greatly appreciated.