Skip to content

Instantly share code, notes, and snippets.

@Stanzilla
Forked from Gnarfoz/Windows event filter
Created April 23, 2014 20:33
Show Gist options
  • Save Stanzilla/11231365 to your computer and use it in GitHub Desktop.
Save Stanzilla/11231365 to your computer and use it in GitHub Desktop.
<QueryList>
<Query Id="0" Path="Security">
<Select Path="Security">*[System[(Level=0) and (EventID=4688)]] and (*[EventData[Data[@Name='NewProcessName'] and (Data='C:\WoW\WoW-64.exe')]])</Select>
</Query>
</QueryList>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment