Skip to content

Instantly share code, notes, and snippets.

@Shivammalaviya
Last active July 30, 2021 09:19
Show Gist options
  • Save Shivammalaviya/57e1eb9e7d3767e7941c8614cb364cb4 to your computer and use it in GitHub Desktop.
Save Shivammalaviya/57e1eb9e7d3767e7941c8614cb364cb4 to your computer and use it in GitHub Desktop.
SecurityEvent
| where ((EventID == 5007) and (NewValue contains @'\Microsoft\Windows Defender\Exclusions'))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment