Hi all,

I'll start by saying i'm a complete rookie with OSSEC, but i know what i am 
looking to setup:

I have sysmon on my windows agent, reporting back some good info, including 
powershell usage.

What i'd like to do on my OSSEC server is setup an alert rule to trigger 
when usage of specific powershell commands is logged by sysmon, in 
particular "-noprofile" and "-ExecutionPolicy Unrestricted" 

Can anybody offer me some noobie pointers on how to go about this? 



