[ - recovery mode ] PowerShell -. I: |
WMI
. , WQL.Win32_Process
, .Get-WMIObject
. WQL .select Name, ProcessId, CommandLine from Win32_Process
AWS.Out-GridView
PowerShell, .Register-WmiEvent
PowerShell 2.0 . , , , .CIM_DataFile.
, , .Register-WmiEvent
, .Register-WmiEvent -Query "SELECT * FROM __InstanceModificationEvent WITHIN 5 WHERE TargetInstance isa 'CIM_DataFile' and TargetInstance.FileSize > 2000000 and TargetInstance.Path = '\\Users\\bob\' and targetInstance.Drive = 'C:' "-sourceIdentifier "Accessor3" -Action { Write-Host "Large file" $EventArgs.NewEvent.TargetInstance.Name "was created}
CIM_DataFile
, 2 . , , , InstanceModificationEvent.