Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- $XML = @'
- <ViewerConfig>
- <QueryConfig>
- <QueryParams>
- <UserQuery />
- </QueryParams>
- <QueryNode>
- <Name>Process Creation</Name>
- <Description>Process Creation and Command-line Auditing Events</Description>
- <QueryList>
- <Query Id="0" Path="Security">
- <Select Path="Security">*[System[(EventID=4688)]]</Select>
- </Query>
- </QueryList>
- </QueryNode>
- </QueryConfig>
- </ViewerConfig>
- '@
- if (-not (Test-Path -Path "$env:ProgramData\Microsoft\Event Viewer\Views"))
- {
- New-Item -Path "$env:ProgramData\Microsoft\Event Viewer\Views" -ItemType Directory -Force
- }
- # Saving ProcessCreation.xml in UTF-8 encoding
- # Сохраняем ProcessCreation.xml в кодировке UTF-8
- Set-Content -Path "$env:ProgramData\Microsoft\Event Viewer\Views\ProcessCreation.xml" -Value (New-Object -TypeName System.Text.UTF8Encoding).GetBytes($XML) -Encoding Byte -Force
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement