Oops I click it again — exercise using a Win7 VM, Graylog & PowerShell Empire. The Win7 VM ran Sysmon, PowerShell 5.1 & NXLog forwarding into Graylog: If you have written about your log collection…