Skip to content

Instantly share code, notes, and snippets.

@tuantmb
Forked from mattifestation/EnableAMSILogging.ps1
Created April 2, 2019 15:33
Show Gist options
  • Save tuantmb/72345a9417bf7742bf82570260803f40 to your computer and use it in GitHub Desktop.
Save tuantmb/72345a9417bf7742bf82570260803f40 to your computer and use it in GitHub Desktop.
Enables AMSI logging to the AMSI/Operational event log
# Run this elevated, reboot, boom.
# Feel free to name this whatever you want
$AutoLoggerName = 'MyAMSILogger'
$AutoLoggerGuid = "{$((New-Guid).Guid)}"
New-AutologgerConfig -Name $AutoLoggerName -Guid $AutoLoggerGuid -Start Enabled
Add-EtwTraceProvider -AutologgerName $AutoLoggerName -Guid '{2A576B87-09A7-520E-C21A-4942F0271D67}' -Level 0xff -MatchAnyKeyword 0x80000000000001 -Property 0x41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment