This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
$ErrorActionPreference = "Stop" | |
# Define the Sysmon archive path, desired quota and query delay. | |
$Archive_clean = "C:\Sysmon\" | |
$Archive = $Archive_clean.Replace("\", "\\") | |
$Limit = 2GB | |
$Delay = 10 | |
$FilterName = "SysmonArchiveWatcher" | |
Write-Verbose "New WMI filter: $FilterName" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#Requires -RunAsAdministrator | |
<# | |
.Synopsis | |
Generates Sysmon Archive file quota for `File Delete` events to help managing the size. | |
.DESCRIPTION | |
Based on: https://blog.nviso.eu/2022/06/30/enforcing-a-sysmon-archive-quota/ | |
.INPUTS | |
None. Cmdlet does not accept pipe values. | |
.OUTPUTS |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<?xml version="1.0" encoding="UTF-8"?> | |
<MitigationPolicy> | |
<SystemConfig> | |
<SEHOP Audit="true"/> | |
</SystemConfig> | |
<AppConfig Executable="iexplore.exe"> | |
<ImageLoad AuditImageLoad="true"/> | |
<Payload AuditEnableExportAddressFilter="true" | |
AuditEnableExportAddressFilterPlus="true" | |
AuditEnableImportAddressFilter="true" |