Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
Enables AMSI logging to the AMSI/Operational event log
$AutoLoggerName = 'MyAMSILogger'
$AutoLoggerGuid = "{$((New-Guid).Guid)}"
New-AutologgerConfig -Name $AutoLoggerName -Guid $AutoLoggerGuid -Start Enabled
Add-EtwTraceProvider -AutologgerName $AutoLoggerName -Guid '{2A576B87-09A7-520E-C21A-4942F0271D67}' -Level 0xff -MatchAnyKeyword ([UInt64] (0x8000000000000001 -band ([UInt64]::MaxValue))) -Property 0x41
@fabamatic

This comment has been minimized.

Copy link

@fabamatic fabamatic commented May 4, 2021

Unless I am getting something wrong AMSI/Operational seems to have dissapeared in newer Windows 10 versions

@johnmccash

This comment has been minimized.

Copy link

@johnmccash johnmccash commented Aug 17, 2021

It does indeed appear to be gone in Win10 20H2. That said, I was never able to get anything logged previously using this technique, though I'm really not certain why.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment