Added code to support flagging suspicious wmi filter events, also added sample log file
This commit is contained in:
BIN
evtx/wmi-event-filter-persistance.evtx
Normal file
BIN
evtx/wmi-event-filter-persistance.evtx
Normal file
Binary file not shown.
Reference in New Issue
Block a user