Updated the examples table
This commit is contained in:
11
README.md
11
README.md
@ -113,16 +113,19 @@ See 'Logging setup' section below for how to configure these logs
|
|||||||
|
|
||||||
|Event|Command|
|
|Event|Command|
|
||||||
|-----|-------|
|
|-----|-------|
|
||||||
|
|Metasploit native target (security log)|` .\DeepBlue.ps1 .\evtx\metasploit-psexec-native-target-security.evtx`|
|
||||||
|
|Metasploit native target (system log)|` .\DeepBlue.ps1 .\evtx\metasploit-psexec-native-target-system.evtx`|
|
||||||
|
|Mimikatz hashdump|`.\DeepBlue.ps1 .\evtx\mimikatz-privesc-hashdump.evtx`|
|
||||||
|
|New user creation|`.\DeepBlue.ps1 .\evtx\new-user-security.evtx`|
|
||||||
|Obfuscation (encoding)|`.\DeepBlue.ps1 .\evtx\Powershell-Invoke-Obfuscation-string-menu.evtx\`|
|
|Obfuscation (encoding)|`.\DeepBlue.ps1 .\evtx\Powershell-Invoke-Obfuscation-string-menu.evtx\`|
|
||||||
|Obfuscation (string)|`.\DeepBlue.ps1 .\evtx\Powershell-Invoke-Obfuscation-string-menu.evtx`|
|
|Obfuscation (string)|`.\DeepBlue.ps1 .\evtx\Powershell-Invoke-Obfuscation-string-menu.evtx`|
|
||||||
|Password guessing|`.\DeepBlue.ps1 .\evtx\smb-password-guessing-security.evtx`|
|
|Password guessing|`.\DeepBlue.ps1 .\evtx\smb-password-guessing-security.evtx`|
|
||||||
|Password spraying|`.\DeepBlue.ps1 .\evtx\password-spray.evtx`|
|
|Password spraying|`.\DeepBlue.ps1 .\evtx\password-spray.evtx`|
|
||||||
|Mimikatz hashdump|`.\DeepBlue.ps1 .\evtx\mimikatz-privesc-hashdump.evtx`|
|
|PowerSploit (security log)|`.\DeepBlue.ps1 .\evtx\powersploit-security.evtx`|
|
||||||
|New user creation|`.\DeepBlue.ps1 .\evtx\new-user-security.evtx`|
|
|PowerSploit (system log)|`.\DeepBlue.ps1 .\evtx\powersploit-system.evtx`|
|
||||||
|
|PSAttack|`.\DeepBlue.ps1 .\evtx\psattack-security.evtx`|
|
||||||
|User added to administrator group|`.\DeepBlue.ps1 .\evtx\new-user-security.evtx`|
|
|User added to administrator group|`.\DeepBlue.ps1 .\evtx\new-user-security.evtx`|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## Logging setup
|
## Logging setup
|
||||||
|
|
||||||
### Security event 4688 (Command line auditing):
|
### Security event 4688 (Command line auditing):
|
||||||
|
Reference in New Issue
Block a user