Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Created August 31, 2023 20:30
Show Gist options
  • Save MHaggis/a3ce0575f7e424419d22c14445005d3f to your computer and use it in GitHub Desktop.
Save MHaggis/a3ce0575f7e424419d22c14445005d3f to your computer and use it in GitHub Desktop.

Inventory Protocol Handlers

Splunk:

[powershell://LOLProtocolHandlers]
script = Get-Item Registry::HKEY_CLASSES_ROOT\*| Select-Object "Property", "PSChildName"  | ForEach-Object { $_ | ConvertTo-Json; Write-Host "" }
#schedule = 0 0 * * *
schedule = */1 * * * *
sourcetype = PwSh:LOLProtocolHandlers
index=win 

Or just run this:

Get-Item Registry::HKEY_CLASSES_ROOT\*| Select-Object "Property", "PSChildName"  | ForEach-Object { $_ | ConvertTo-Json; Write-Host "" }
@cyberbuff
Copy link

Mac Protocol Handlers can be found using this

/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump URLSchemeBinding

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment