Create a gist now

Instantly share code, notes, and snippets.

What would you like to do?
if not exist "C:\windows\sysmon_config.xml" (
copy /z /y "\\lab.local\SYSVOL\lab.local\scripts\sysmon\sysmon_config.xml" "C:\windows\"
)
sc query "Sysmon" | Find "RUNNING"
If "%ERRORLEVEL%" EQU "1" (
goto startsysmon
)
:startsysmon
net start Sysmon
If "%ERRORLEVEL%" EQU "1" (
goto installsysmon
)
:installsysmon
"\\lab.local\SYSVOL\lab.local\scripts\sysmon\sysmon64.exe" /accepteula -i c:\windows\sysmon_config.xml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment