Advertisement
cwprogram

WMI Event Listeners

Jul 12th, 2011
503
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.17 KB | None | 0 0
  1. Original Article: http://technet.microsoft.com/en-us/library/ff730927.aspx
  2. Code showing updated "Get-Event" instead of "Get-PSEvent"
  3.  
  4. PS > Register-WMIEvent -query "Select * From __InstanceCreationEvent within 3 Where TargetInstance ISA 'Win32_Process'" `
  5. -messageData "A new process has started." -sourceIdentifier "New Process"
  6.  
  7. ___________________________________________________________________________________
  8.  
  9. # Run calc.exe
  10.  
  11. PS > Get-Event -SourceIdentifier "New Process"
  12.  
  13.  
  14. ComputerName :
  15. RunspaceId : 2a7e4118-3ad2-4ef8-872f-a52924202574
  16. EventIdentifier : 4
  17. Sender : System.Management.ManagementEventWatcher
  18. SourceEventArgs : System.Management.EventArrivedEventArgs
  19. SourceArgs : {System.Management.ManagementEventWatcher, System.Management.EventArrivedEventArg
  20. s}
  21. SourceIdentifier : New Process
  22. TimeGenerated : 7/12/2011 4:24:09 PM
  23. MessageData : A new process has started.
  24.  
  25.  
  26.  
  27.  
  28. ______________________________________________________________________________________
  29. PS > Unregister-Event -SourceIdentifier "New Process"
  30. ______________________________________________________________________________________
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement