-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
I am researching using WmiEvent and Uproot but have several questions.
- Is there more documentation?
- Uproot overview does not have WmiEvent implemented. Are there plans to do so?
- If I am already monitoring process creations with the native security log with command-line arguments included, is there any benefit to monitoring them using WMI?
- I don't see either tool, by default, monitoring the deletion of a class (defensive monitoring of persistence)? Is this something I would add?
Look forward to the replies.
Thanks in advance. #
Metadata
Metadata
Assignees
Labels
No labels