Skip to content

Instantly share code, notes, and snippets.

@mySYSMON
mySYSMON / poc-domainrank-WithBugs.ps1
Created December 18, 2020 19:24
poc-domainrank-WithBugs.ps1
#free bugs, use for reference only
#free bugs, use for reference only
Function poc-dns1 {
[CmdletBinding()]
param(
#[Parameter(Mandatory=$true)]
@mySYSMON
mySYSMON / sysmon1-stats-count-by-image.ps1
Last active December 12, 2020 01:04
sysmon1-stats-count-by-image.ps1
$events = Get-WinEvent -FilterHashtable `
@{ `
logname='Microsoft-Windows-Sysmon/Operational'; `
id=1; `
StartTime=(Get-Date).AddHours(-1); `
EndTime=get-date `
}
$dict = @{}
foreach ($log in $events)
{
@mySYSMON
mySYSMON / pullSysmon1events.cpp
Last active November 29, 2020 12:37
working example pulling sysmon 1 events
#include <windows.h>
#include <conio.h>
#include <stdio.h>
#include <winevt.h>
#pragma comment(lib, "wevtapi.lib")
#define ARRAY_SIZE 10
DWORD EnumerateResults(EVT_HANDLE hResults);