|
| 1 | +Author: Andrew Rathbun |
| 2 | +Description: Pipeline Execution Details |
| 3 | +EventId: 800 |
| 4 | +Channel: Windows PowerShell |
| 5 | +Provider: PowerShell |
| 6 | +Maps: |
| 7 | + - |
| 8 | + Property: PayloadData1 |
| 9 | + PropertyValue: "%HostApplication%" |
| 10 | + Values: |
| 11 | + - |
| 12 | + Name: HostApplication |
| 13 | + Value: "/Event/EventData/Data" |
| 14 | + Refine: "HostApplication=(.+)" |
| 15 | + - |
| 16 | + Property: PayloadData2 |
| 17 | + PropertyValue: "%HostName%" |
| 18 | + Values: |
| 19 | + - |
| 20 | + Name: HostName |
| 21 | + Value: "/Event/EventData/Data" |
| 22 | + Refine: "HostName=(.+)" |
| 23 | + - |
| 24 | + Property: PayloadData3 |
| 25 | + PropertyValue: "%HostVersion%" |
| 26 | + Values: |
| 27 | + - |
| 28 | + Name: HostVersion |
| 29 | + Value: "/Event/EventData/Data" |
| 30 | + Refine: "HostVersion=(.+)" |
| 31 | + |
| 32 | +# Documentation: |
| 33 | +# https://www.myeventlog.com/search/show/975 |
| 34 | +# |
| 35 | +# Example Event Data: |
| 36 | +# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> |
| 37 | +# <System> |
| 38 | +# <Provider Name="PowerShell" /> |
| 39 | +# <EventID Qualifiers="0">600</EventID> |
| 40 | +# <Level>4</Level> |
| 41 | +# <Task>6</Task> |
| 42 | +# <Keywords>0x80000000000000</Keywords> |
| 43 | +# <TimeCreated SystemTime="2001-01-01T01:01:01.012345678Z" /> |
| 44 | +# <EventRecordID>18</EventRecordID> |
| 45 | +# <Channel>Windows PowerShell</Channel> |
| 46 | +# <Computer>name.domain.tld</Computer> |
| 47 | +# <Security /> |
| 48 | +# </System> |
| 49 | +# <EventData> |
| 50 | +# <Data>Registry, Started, ProviderName=Registry |
| 51 | +# NewProviderState=Started |
| 52 | +# |
| 53 | +# SequenceNumber=1 |
| 54 | +# |
| 55 | +# HostName=ConsoleHost |
| 56 | +# HostVersion=5.1.18362.145 |
| 57 | +# HostId=b3dfcb89-d2f8-4b8b-a784-a6a9bcf61bd8 |
| 58 | +# HostApplication=powershell -command Set-ItemProperty -Path HKCU:\Software\Microsoft\Office\16.0\Outlook\AutoDiscover -Name 'ExcludeExplicitO365Endpoint' -Value 1 -Type DWORD -Force |
| 59 | +# EngineVersion= |
| 60 | +# RunspaceId= |
| 61 | +# PipelineId= |
| 62 | +# CommandName= |
| 63 | +# CommandType= |
| 64 | +# ScriptName= |
| 65 | +# CommandPath= |
| 66 | +# CommandLine=</Data> |
| 67 | +# </EventData> |
| 68 | +# </Event> |
0 commit comments