Skip to content

Instantly share code, notes, and snippets.

Last active March 28, 2018 21:34
Show Gist options
  • Save csereno/ffcfdca2a26548eb1dd62653ac49e901 to your computer and use it in GitHub Desktop.
Save csereno/ffcfdca2a26548eb1dd62653ac49e901 to your computer and use it in GitHub Desktop.
PowerShell script to delete old captures, archive current ones, and start a new one. Also includes a Windows scheduled task template
# Created by csereno
# 3/28/2018
# PowerShell script to delete captures older than 14 days, archive current ones, and start a new one using WinDump.
# Works with PowerShell 2016 and requires WinDump.exe
# Note: Changes will be needed to work with different environments.
$ArchivePath = "C:\Temp\CaptureArchive"
$CapturePath = "C:\Temp\Captures"
$Daysback = "-14"
$CurrentDate = Get-Date
$DatetoDelete = $CurrentDate.AddDays($Daysback)
# Delete all Files in the archive older than 14 day(s)
Get-ChildItem $ArchivePath | Where-Object { $_.LastWriteTime -lt $DatetoDelete } | Remove-Item
#Kill the current capture process
Stop-Process -Name "WinDump" -Force
# Archive current files and copy them to the Archive directory
Compress-Archive -Path $CapturePath -DestinationPath $ArchivePath\$
# Delete the current capture files
Remove-Item "$CapturePath\*.*" | Where { ! $_.PSIsContainer }
#Start WinDump again using a ring buffer of 100 files of 40MB each
& "C:\Temp\windump.exe" -i1 -n -t -s 1514 -W 100 -C 40 -w "$CapturePath\temp.pcap" not port 3389
<!-- Windows Scheduled Task Template -->
<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="">
<Wednesday />
<Principal id="Author">
<Actions Context="Author">
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment