Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Forked from thinkst-cs/get_cmdline.reg
Created September 8, 2022 13:11
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save MHaggis/bf19006da15bdc1de92ce37127eb64aa to your computer and use it in GitHub Desktop.
Save MHaggis/bf19006da15bdc1de92ce37127eb64aa to your computer and use it in GitHub Desktop.
Monitoring Silent Process Exit
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\nltest.exe]
"ReportingMode"=dword:00000001
"MonitorProcess"="powershell.exe -Command \"Get-WmiObject win32_process -Filter 'ProcessID = %e' | select CreationDate,ProcessId,CommandLine >> C:\\\\Test\\\\Logcmdline.txt\""
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment