Skip to content

Instantly share code, notes, and snippets.

@wecsam
Created March 23, 2018 22:27
Show Gist options
  • Select an option

  • Save wecsam/fef41704af77187f481d5f261d08ff10 to your computer and use it in GitHub Desktop.

Select an option

Save wecsam/fef41704af77187f481d5f261d08ff10 to your computer and use it in GitHub Desktop.
Displays events from the last day that are related to Controlled Folder Access in Windows 10
@REM Pull events with IDs 1123, 1124, and 5007 from the last day.
@REM Get-WinEvent "Microsoft-Windows-Windows Defender/Operational" | ? { $_.Id -eq 1123 -or $_.Id -eq 1124 -or $_.Id -eq 5007 } | ? { ((Get-Date) - $_.TimeCreated).TotalDays -le 1 } | Format-List
@powershell -EncodedCommand RwBlAHQALQBXAGkAbgBFAHYAZQBuAHQAIAAiAE0AaQBjAHIAbwBzAG8AZgB0AC0AVwBpAG4AZABvAHcAcwAtAFcAaQBuAGQAbwB3AHMAIABEAGUAZgBlAG4AZABlAHIALwBPAHAAZQByAGEAdABpAG8AbgBhAGwAIgAgAHwAIAA/ACAAewAgACQAXwAuAEkAZAAgAC0AZQBxACAAMQAxADIAMwAgAC0AbwByACAAJABfAC4ASQBkACAALQBlAHEAIAAxADEAMgA0ACAALQBvAHIAIAAkAF8ALgBJAGQAIAAtAGUAcQAgADUAMAAwADcAIAB9ACAAfAAgAD8AIAB7ACAAKAAoAEcAZQB0AC0ARABhAHQAZQApACAALQAgACQAXwAuAFQAaQBtAGUAQwByAGUAYQB0AGUAZAApAC4AVABvAHQAYQBsAEQAYQB5AHMAIAAtAGwAZQAgADEAIAB9ACAAfAAgAEYAbwByAG0AYQB0AC0ATABpAHMAdAA=
@PAUSE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment