Closed clong closed 6 years ago
https://github.com/palantir/windows-event-forwarding/blob/master/AutorunsToWinEventLog/AutorunsToWinEventLog.ps1#L20
Specifically slide 14 and 15: https://github.com/huntresslabs/evading-autoruns/blob/master/Evading_Autoruns_Slides.pdf
Handled via branch: https://github.com/palantir/windows-event-forwarding/pull/13
https://github.com/palantir/windows-event-forwarding/blob/master/AutorunsToWinEventLog/AutorunsToWinEventLog.ps1#L20
Specifically slide 14 and 15: https://github.com/huntresslabs/evading-autoruns/blob/master/Evading_Autoruns_Slides.pdf