Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <Sysmon schemaversion="3.30">
- <HashAlgorithms>MD5,SHA1,SHA256</HashAlgorithms>
- <EventFiltering>
- <ProcessAccess onmatch="include">
- <SourceImage condition="contains">powershell.exe</SourceImage>
- </ProcessAccess>
- </EventFiltering>
- </Sysmon>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement