Generated docs from job=generate-docs branch=master [ci skip]
This commit is contained in:
@@ -97261,8 +97261,8 @@ discovery:
|
||||
supported_platforms:
|
||||
- windows
|
||||
executor:
|
||||
command: powershell -c "get-eventlog 'Security' | where {$_.Message -like
|
||||
'*SYSTEM*'} | export-csv $env:temp\T1654_events.txt"
|
||||
command: powershell -c {get-eventlog 'Security' | where {$_.Message -like
|
||||
'*SYSTEM*'} | export-csv $env:temp\T1654_events.txt}
|
||||
cleanup_command: powershell -c "remove-item $env:temp\T1654_events.txt -ErrorAction
|
||||
Ignore"
|
||||
name: powershell
|
||||
|
||||
@@ -79162,8 +79162,8 @@ discovery:
|
||||
supported_platforms:
|
||||
- windows
|
||||
executor:
|
||||
command: powershell -c "get-eventlog 'Security' | where {$_.Message -like
|
||||
'*SYSTEM*'} | export-csv $env:temp\T1654_events.txt"
|
||||
command: powershell -c {get-eventlog 'Security' | where {$_.Message -like
|
||||
'*SYSTEM*'} | export-csv $env:temp\T1654_events.txt}
|
||||
cleanup_command: powershell -c "remove-item $env:temp\T1654_events.txt -ErrorAction
|
||||
Ignore"
|
||||
name: powershell
|
||||
|
||||
@@ -35,7 +35,7 @@ Successful execution will save matching log events to the users temp folder.
|
||||
|
||||
|
||||
```powershell
|
||||
powershell -c "get-eventlog 'Security' | where {$_.Message -like '*SYSTEM*'} | export-csv $env:temp\T1654_events.txt"
|
||||
powershell -c {get-eventlog 'Security' | where {$_.Message -like '*SYSTEM*'} | export-csv $env:temp\T1654_events.txt}
|
||||
```
|
||||
|
||||
#### Cleanup Commands:
|
||||
|
||||
Reference in New Issue
Block a user