Hi, i find the results output for QID 45254 PowerShell Detected on Host confusing. Why would it show two versions for the same EXE?
HKLM\SOFTWARE\Microsoft\PowerShell\1\PowerShellEngine PowerShellVersion = 2.0
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe found
HKLM\SOFTWARE\Microsoft\PowerShell\3\PowerShellEngine PowerShellVersion = 5.1.17134.1
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe found
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\PowerShellEngine PowerShellVersion = 2.0
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe found
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\3\PowerShellEngine PowerShellVersion = 5.1.17134.1
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe found
At this present time i can't work out the query string in Global Asset Management module to display PowerShell, and wonder whether it wouldn't do the same thing, based on above output?
Thanks, Tony
32 vs 64-bit versions of Powershell.