-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


[ - recovery mode ] PowerShell -. I:

, 08 2017 . 16:20 +


, , , PowerShell. : PowerShell . , PowerShell.

, , PowerShell ( Varonis ), - . , - , Metadata Framework. PowerShell , .



PowerShell , .

, , , . , , Linux , , , , .

.

PowerShell - . .

PowerShell , . , ( ). .

, .

, , , , , .

(, Linux Windows) , , , .

, , , . ( , , . .), . .

. PowerShell .



Windows (WMI), Microsoft .

WMI, , (WBEM), , , , , .

WMI?

, SQL, WMI. , WQL.

Windows WBEMTest, WQL. Win32_Process, .

image
WQL WBEMTest

Windows. , ? WQL, (Ravi Chaganti), .

PowerShell Register-WmiEvent

. WBEMTest PowerShell.

PowerShell Get-WMIObject. WQL .

select Name, ProcessId, CommandLine from Win32_Process AWS.


gwmi Get-WmiObject PowerShell

, , . , .

Win32_Process Out-GridView PowerShell, .



PowerShell. WMI , .

, . WMI : , .

PowerShell 2.0 : , , . , MS Technet.

Register-WmiEvent PowerShell 2.0 . , , , .

( ) Acme, - AWS.

( ) , Salsa . , Acme , , , Taco.

: , .

, CIM_DataFile. , , .


PowerShell CIM_DataFile

Register-WmiEvent, .

Register-WmiEvent -Query "SELECT * FROM __InstanceModificationEvent WITHIN 5 WHERE TargetInstance isa 'CIM_DataFile' and TargetInstance.FileSize > 2000000 and TargetInstance.Path = '\\Users\\bob\' and targetInstance.Drive = 'C:' "-sourceIdentifier "Accessor3" -Action { Write-Host "Large file" $EventArgs.NewEvent.TargetInstance.Name "was created}

Salsa Register-WmiEvent , . .

. WQL \Users\bob CIM_DataFile, 2 . , , , InstanceModificationEvent.

, , PowerShell, , , MP4 . .


, . !

PowerShell .

.
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/335176/

:  

: [1] []
 

:
: 

: ( )

:

  URL