Advertisement
Wintersham

установлен ли sysmon powershell

Apr 10th, 2024 (edited)
636
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. cls
  2. del C:\users\BuharskyAA\Documents\ADComputers.csv
  3. Get-ADComputer -Filter * -Properties * -SearchBase "CN=Computers,DC=fkp47,DC=local"| select Name | Export-Csv C:\users\BuharskyAA\Documents\ADComputers.csv
  4. Get-Content C:\users\BuharskyAA\Documents\ADComputers.csv
  5. $ADComputers_without_header = Import-Csv C:\users\BuharskyAA\Documents\ADComputers.csv | Select-Object -ExpandProperty Name
  6.  
  7. cls
  8. del C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  9. New-Item C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  10. for ($i = 0;$i -le 318; $i++){
  11. $search_path = "\\" + $ADComputers_without_header[$i] + "\" + "c$" + "\" + "Windows"
  12. $search_file = Get-ChildItem -Name  $search_path | Select-String -SimpleMatch "sysmon.exe"}
  13. if ( $search_file.Count -eq 1){
  14.  
  15.   $ADComputers_without_header[$i] >> C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  16.  
  17.   Get-Content  C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  18.  
  19.  else
  20.  
  21.  "Совпадения не найдено"
  22. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement