Skip to content

Questions #1

@rdram0s

Description

@rdram0s

I am researching using WmiEvent and Uproot but have several questions.

  1. Is there more documentation?
  2. Uproot overview does not have WmiEvent implemented. Are there plans to do so?
  3. If I am already monitoring process creations with the native security log with command-line arguments included, is there any benefit to monitoring them using WMI?
  4. I don't see either tool, by default, monitoring the deletion of a class (defensive monitoring of persistence)? Is this something I would add?

Look forward to the replies.

Thanks in advance. #

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions