New features were introduced in Windows 10 and O365 where the commonly-abused scripting engine components that execute PowerShell, JavaScript, Visual Basic Script, HTA files, and Office Macros are instrumented to create AMSI calls into security products and to produce event logs. This instrumentation contains dynamically-loaded script content, as well as behavior instrumentation logs of the scripts during execution. In this presentation, we will present an example use case of how we use the behavior instrumentation feature combined with machine learning in Windows Defender ATP to protect against attacks in real time by pairing lightweight client behavior models with heavier real-time cloud models. We'll also talk about how some of these AMSI events are logged for you to look at within your enterprise.