Update README.md

This commit is contained in:
Eric Conrad
2016-09-20 12:25:48 -04:00
committed by GitHub
parent 7adb6214bf
commit 023e9727f3

View File

@ -10,6 +10,7 @@ Sample evtx files are in the .\evtx directory
## Usage: ## Usage:
` `
.\DeepBlue.ps1 <event log name> <evtx filename> .\DeepBlue.ps1 <event log name> <evtx filename>
` `
@ -17,26 +18,36 @@ Sample evtx files are in the .\evtx directory
## Examples: ## Examples:
Process local Windows security event log: Process local Windows security event log:
` `
.\DeepBlue.ps1 .\DeepBlue.ps1
` `
or: or:
` `
.\DeepBlue.ps1 -log security .\DeepBlue.ps1 -log security
` `
Process local Windows system event log: Process local Windows system event log:
` `
.\DeepBlue.ps1 -log system .\DeepBlue.ps1 -log system
` `
or: or:
` `
.\DeepBlue.ps1 "" system .\DeepBlue.ps1 "" system
` `
Process evtx file: Process evtx file:
` `
.\DeepBlue.ps1 .\evtx\new-user-security.evtx .\DeepBlue.ps1 .\evtx\new-user-security.evtx
` `
or: or:
` `
.\DeepBlue.ps1 -file .\evtx\new-user-security.evtx .\DeepBlue.ps1 -file .\evtx\new-user-security.evtx
` `