Technical Information
- [<HKLM>\System\CurrentControlSet\Services\sysmon64] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\sysmon64] 'ImagePath' = '%WINDIR%\sysmon64.exe'
- [<HKLM>\System\CurrentControlSet\Services\SysmonDrv] 'Start' = '00000000'
- [<HKLM>\System\CurrentControlSet\Services\SysmonDrv] 'ImagePath' = 'SysmonDrv.sys'
- [<HKLM>\System\CurrentControlSet\Services\winlogbeat] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\winlogbeat] 'ImagePath' = '%ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.exe -c %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.yml -path.home %ALLUSERSPROFI...
- 'sysmon64' %WINDIR%\sysmon64.exe
- 'SysmonDrv' %WINDIR%\SysmonDrv.sys
- 'winlogbeat' %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.exe -c %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.yml -path.home %ALLUSERSPROFILE%\soc\winlogbeat -path.data %ALLUSERSPROFILE%\soc\winlogbeat\data -...
- %TEMP%\auditpol\set_audit_pol_desktop_v1.0.cmd
- %WINDIR%\sysmondrv.sys
- %ALLUSERSPROFILE%\soc\sysmon\service_sddl.txt
- %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.exe
- %ALLUSERSPROFILE%\soc\winlogbeat\certs\ca.crt
- %ALLUSERSPROFILE%\soc\winlogbeat\certs\beat.crt
- %ALLUSERSPROFILE%\soc\winlogbeat\certs\beat.key
- %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.yml
- %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.sum.txt
- %ALLUSERSPROFILE%\soc\winlogbeat\data\meta.json.new
- %ALLUSERSPROFILE%\soc\winlogbeat\logs\winlogbeat
- %WINDIR%\security\audit\audit.csv
- %ALLUSERSPROFILE%\soc\security_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\application_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\system_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\sysmon_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\windows-powershell_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\powershell_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\taskscheduler_operational_ocnylqebon_thu11050547.xml
- %ALLUSERSPROFILE%\soc\auditpol_before_ocnylqebon_thu11050547.csv
- %ALLUSERSPROFILE%\soc\auditpol_after_ocnylqebon_thu11050547.csv
- %TEMP%\man817e.tmp
- %ALLUSERSPROFILE%\soc\winlogbeat\data\.winlogbeat.yml.new
- %WINDIR%\sysmon64.exe
- %TEMP%\winlogbeat\certs\ca.crt
- %TEMP%\auditpol\set_audit_pol_server_ca_v1.0.cmd
- %TEMP%\auditpol\set_audit_pol_server_dc_v1.0.cmd
- %TEMP%\auditpol\set_audit_pol_server_nps_v1.0.cmd
- %TEMP%\auditpol\set_audit_pol_server_v1.0.cmd
- %TEMP%\sysmon\install_sysmon.cmd
- %TEMP%\sysmon\sysmon.sum.txt
- %TEMP%\sysmon\sysmon_config.xml
- %TEMP%\winlogbeat\certs\beat.crt
- %TEMP%\winlogbeat\certs\beat.key
- %TEMP%\winlogbeat\install_winlogbeat.cmd
- %ALLUSERSPROFILE%\soc\sysmon\sysmon.sum.txt
- %TEMP%\winlogbeat\winlogbeat.yml
- %TEMP%\winlogbeat\x64\winlogbeat.sum.txt
- %TEMP%\winlogbeat\x86\winlogbeat.sum.txt
- %TEMP%\sysmon\sysmon.exe
- %TEMP%\sysmon\sysmon64.exe
- %TEMP%\winlogbeat\x64\winlogbeat.exe
- %TEMP%\winlogbeat\x86\winlogbeat.exe
- nul
- %ALLUSERSPROFILE%\soc\sysmon\sysmon64.exe
- %ALLUSERSPROFILE%\soc\sysmon\sysmon_config.xml
- %TEMP%\7zsfx000.cmd
- %TEMP%\man817e.tmp
- %WINDIR%\sysmon64.exe
- %WINDIR%\sysmondrv.sys
- %ALLUSERSPROFILE%\soc\sysmon\sysmon64.exe
- %TEMP%\sysmon\sysmon.exe
- %TEMP%\sysmon\sysmon64.exe
- %TEMP%\winlogbeat\certs\beat.crt
- %TEMP%\winlogbeat\certs\beat.key
- %TEMP%\winlogbeat\certs\ca.crt
- %TEMP%\7zsfx000.cmd
- from %ALLUSERSPROFILE%\soc\winlogbeat\data\meta.json.new to %ALLUSERSPROFILE%\soc\winlogbeat\data\meta.json
- from %ALLUSERSPROFILE%\soc\winlogbeat\data\.winlogbeat.yml.new to %ALLUSERSPROFILE%\soc\winlogbeat\data\.winlogbeat.yml
- DNS ASK co########9.soc.wlaq.qianxin-inc.cn
- DNS ASK co########1.soc.wlaq.qianxin-inc.cn
- DNS ASK co########2.soc.wlaq.qianxin-inc.cn
- DNS ASK co########3.soc.wlaq.qianxin-inc.cn
- DNS ASK co########4.soc.wlaq.qianxin-inc.cn
- DNS ASK co########5.soc.wlaq.qianxin-inc.cn
- DNS ASK co########6.soc.wlaq.qianxin-inc.cn
- DNS ASK co########7.soc.wlaq.qianxin-inc.cn
- DNS ASK co########8.soc.wlaq.qianxin-inc.cn
- '%ALLUSERSPROFILE%\soc\sysmon\sysmon64.exe' -accepteula -i "%ALLUSERSPROFILE%\soc\sysmon\Sysmon_config.xml"
- '%WINDIR%\sysmon64.exe' -nologo -accepteula -m
- '%TEMP%\winlogbeat\x64\winlogbeat.exe' version
- '%ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.exe' -c %ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.yml -path.home %ALLUSERSPROFILE%\soc\winlogbeat -path.data %ALLUSERSPROFILE%\soc\winlogbeat\data -path.logs %ALLUSERSPROFILE%\soc\winlogbeat\logs
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Sysmon\install_sysmon.cmd" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Winlogbeat\install_winlogbeat.cmd" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Auditpol\Set_Audit_Pol_Desktop_v1.0.cmd" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Sysmon\install_sysmon.cmd" "
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921F-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921E-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921D-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9249-69AE-11D9-BED3-505054503030} /success:enable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9247-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9243-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921C-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921B-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE921A-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9219-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9218-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9239-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9217-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9215-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923E-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923D-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923C-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923B-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE924A-69AE-11D9-BED3-505054503030} /success:enable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9248-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922E-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922D-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922C-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922B-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9216-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923A-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9220-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9232-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /backup /file:%WINDIR%\security\audit\audit.csv
- '%WINDIR%\syswow64\auditpol.exe' /backup /file:%ALLUSERSPROFILE%\soc\AuditPol_AFTER_ocnylqebon_Thu11050547.csv
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9214-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9213-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9212-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9211-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9210-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922A-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9229-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9228-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9234-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9222-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9221-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9231-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9230-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE922F-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9246-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9245-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9244-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9227-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9226-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9225-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9224-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9223-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9233-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9238-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9237-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9236-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\wevtutil.exe' gl "Application" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' gl "Security" /f:xml
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Auditpol\Set_Audit_Pol_Desktop_v1.0.cmd" "
- '%WINDIR%\syswow64\sc.exe' sdset winlogbeat "D:(D;;DCLCWPDTSD;;;IU)(D;;DCLCWPDTSD;;;SU)(D;;DCLCWPDTSD;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)S:(AU...
- '%WINDIR%\syswow64\net1.exe' start winlogbeat
- '%WINDIR%\syswow64\net.exe' start winlogbeat
- '%WINDIR%\syswow64\sc.exe' failure winlogbeat actions= restart/10000/restart/10000/restart/10000 reset= 120
- '%WINDIR%\syswow64\sc.exe' create winlogbeat binPath= ""%ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.exe" -c "%ALLUSERSPROFILE%\soc\winlogbeat\winlogbeat.yml" -path.home "%ALLUSERSPROFILE%\soc\winlogbeat" -path.data "%ALL...
- '%WINDIR%\syswow64\sc.exe' qc winlogbeat 5000
- '%WINDIR%\syswow64\cmd.exe' /c sc qc winlogbeat 5000
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-Sysmon/Operational" /f:xml
- '%WINDIR%\syswow64\sc.exe' sdset winlogbeat D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Winlogbeat\install_winlogbeat.cmd" "
- '%WINDIR%\syswow64\sc.exe' sdset sysmon64 "D:(D;;DCLCWPDTSD;;;IU)(D;;DCLCWPDTSD;;;SU)(D;;DCLCWPDTSD;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)S:(AU;F...
- '%WINDIR%\syswow64\sc.exe' config sysmon64 start= delayed-auto
- '%WINDIR%\syswow64\sc.exe' sdshow sysmon64
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-Sysmon/Operational" /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-Sysmon/Operational" /ms:52428800
- '%WINDIR%\syswow64\sc.exe' failure Sysmon64 actions= restart/10000/restart/10000/restart/10000 reset= 120
- '<SYSTEM32>\wevtutil.exe' im "%TEMP%\MAN817E.tmp"
- '%WINDIR%\syswow64\timeout.exe' /t 5
- '%WINDIR%\syswow64\cmd.exe' /c time /t
- '%WINDIR%\syswow64\cmd.exe' /c date /t
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\Winlogbeat\\x64\winlogbeat.exe version
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-PowerShell/Operational" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' gl "System" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' gl "Windows PowerShell" /f:xml
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9235-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-TaskScheduler/Maintenance" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9242-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9241-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE9240-69AE-11D9-BED3-505054503030} /success:disable /failure:disable
- '%WINDIR%\syswow64\auditpol.exe' /set /subcategory:{0CCE923F-69AE-11D9-BED3-505054503030} /success:enable /failure:enable
- '%WINDIR%\syswow64\auditpol.exe' /backup /file:%ALLUSERSPROFILE%\soc\AuditPol_BEFORE_ocnylqebon_Thu11050547.csv
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" /v EnableScriptBlockInvocationLogging /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" /v EnableScriptBlockLogging /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames" /v * /t REG_SZ /d "*" /f
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging" /v EnableModuleLogging /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' add "hklm\System\CurrentControlSet\Control\Lsa" /v SCENoApplyLegacyAuditPolicy /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' add "hklm\software\microsoft\windows\currentversion\policies\system\audit" /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-TaskScheduler/Operational" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-WMI-Activity/Operational" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-UserPnp/DeviceInstall" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-WMI-Activity/Operational" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Windows PowerShell" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-PowerShell/Operational" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Microsoft-Windows-Sysmon/Operational" /ms:52428800 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "System" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Application" /ms:20971520 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' sl "Security" /ms:52428800 /rt:false
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-TaskScheduler/Maintenance" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-TaskScheduler/Operational" /f:xml
- '%WINDIR%\syswow64\wevtutil.exe' gl "Microsoft-Windows-UserPnp/DeviceInstall" /f:xml
- '%WINDIR%\syswow64\auditpol.exe' /backup /file:"<SYSTEM32>\GroupPolicy\Machine\Microsoft\Windows NT\Audit\audit.csv"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "