Please let me know the correlation search query and time range conditions for two of these usecases. I have windows powershell logs onboarded.
1. Suspicious Windows Shell Launched by Web Applications
2. Suspicious Windows Shell Launched by a trusted process