Inventory Protocol Handlers
Splunk:
[powershell://LOLProtocolHandlers]
script = Get-Item Registry::HKEY_CLASSES_ROOT\*| Select-Object "Property", "PSChildName" | ForEach-Object { $_ | ConvertTo-Json; Write-Host "" }
#schedule = 0 0 * * *
schedule = */1 * * * *
sourcetype = PwSh:LOLProtocolHandlers
index=win
Or just run this:
Get-Item Registry::HKEY_CLASSES_ROOT\*| Select-Object "Property", "PSChildName" | ForEach-Object { $_ | ConvertTo-Json; Write-Host "" }
Mac Protocol Handlers can be found using this