Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <localfile>
- <log_format>full_command</log_format>
- <command>%COMSPEC% /C type %WINDIR%\system32\drivers\etc\hosts | %WINDIR%\system32\findstr.exe /BVC:"#"</command> <alias>Windows Hosts File</alias>
- </localfile>
- <localfile>
- <log_format>full_command</log_format>
- <command>%WINDIR%\system32\reg.exe query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s | %WINDIR%\system32\findstr.exe /BV "! REG.EXE"</command> <alias>Windows Registry Run Key</alias>
- </localfile>
- <localfile>
- <log_format>full_command</log_format>
- <command>%WINDIR%\system32\reg.exe query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /s | %WINDIR%\system32\findstr.exe /BV "! REG.EXE"</command> <alias>Windows Registry RunOnce Key</alias>
- </localfile>
- <localfile>
- <log_format>full_command</log_format>
- <command>%WINDIR%\system32\reg.exe query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx /s | %WINDIR%\system32\findstr.exe /BV "! REG.EXE"</command> <alias>Windows Registry RunOnceEx Key</alias>
- </localfile>
- <localfile>
- <log_format>full_command</log_format>
- <command>%WINDIR%\system32\net.exe localgroup administrators</command>
- <!-- command>%WINDIR%\system32\net.exe localgroup administrators | %WINDIR%\system32\findstr.exe /BV /C:"Alias name" /C:"Comment Administrators have complete" /C:"Members" /C:"The command completed" /C:"---------"</command -->
- <alias>Windows Administrators Group Members</alias>
- </localfile>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement