Advertisement
Wintersham

установлен ли sysmon powershell

Apr 10th, 2024 (edited)
676
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. cls
  2. del C:\users\BuharskyAA\Documents\ADComputers.csv
  3. #Get-ADComputer -Filter * -Properties * -SearchBase "CN=Computers,DC=fkp47,DC=local"| select Name | Export-Csv C:\users\BuharskyAA\Documents\ADComputers.csv
  4. Get-ADComputer -Filter 'Name -like "IT*"' -SearchBase "CN=Computers,DC=fkp47,DC=local" | Select Name | Export-Csv C:\users\BuharskyAA\Documents\ADComputers.csv
  5. Get-Content C:\users\BuharskyAA\Documents\ADComputers.csv
  6. $ADComputers_without_header = Import-Csv C:\users\BuharskyAA\Documents\ADComputers.csv | Select-Object -ExpandProperty Name
  7. $cnt = $ADComputers_without_header.Count
  8. $cnt
  9.  
  10. cls
  11. del C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  12. New-Item C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  13. for ($i = 0;$i -le $cnt; $i++){
  14. $search_path = "\\" + $ADComputers_without_header[$i] + "\" + "c$" + "\" + "Windows"
  15. $search_path
  16. $search_file = Get-ChildItem -Name  $search_path | Select-String -SimpleMatch "sysmon.exe"
  17. $search_file.Count
  18. if ($search_file.Count -eq 1){
  19.  
  20.   $ADComputers_without_header[$i] >> C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  21.  
  22.   "Результат записан"
  23.  
  24.   Get-Content  C:\Users\BuharskyAA\Documents\Result_sysmon_serach.csv
  25.  
  26.  else
  27.  
  28.  "Совпадения не найдено"
  29. }
  30. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement