Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Olafhartlong sysmon-modular
- #https://github.com/olafhartong/sysmon-modular
- #Run with Admin rights
- #Using NEW Windows Dev Eval VMWare.
- # 1. Open the NEW Windows Terminal with ADMIN and select Ubuntu window
- #git clone https://github.com/olafhartong/sysmon-modular
- Invoke-WebRequest https://github.com/olafhartong/sysmon-modular/archive/refs/heads/master.zip -OutFile "Sysmon-Mod.zip"
- Expand-Archive -LiteralPath C:\Users\labadmin\Sysmon-Mod.zip -DestinationPath $env:tmp
- cd $env:tmp/sysmon-modular-master
- # 2. Grab the Sysmon_v11.11 from my GDrive
- # https://drive.google.com/file/d/1aTYsDic2OZ0DGOCKZWvAw5uvsQE8F-ew/view?usp=sharing
- # 2 ALT.- If you want the newest bleeding edge sysmon
- Invoke-WebRequest https://live.sysinternals.com/Sysmon64.exe -OutFile "sysmon.exe"
- # Put sysmon in the Sysmon_Modular folder
- # Now create the sysmon config file
- Set-ExecutionPolicy -Scope CurrentUser Bypass
- . .\Merge-SysmonXml.ps1
- Merge-AllSysmonXml -Path ( Get-ChildItem '[0-9]*\*.xml') -AsString | Out-File sysmonconfig.xml
- # 5. And Install the sysmon_v11.11 with sysmonconfig file
- ./sysmon.exe -accepteula -i sysmonconfig.xml
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement