āĻĒāĻžāĻ“āϝāĻŧāĻžāϰāĻļ⧇āϞ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇ āϘāϟāύāĻžāϰ āϤāĻĨā§āϝ āϏāĻ‚āĻ—ā§āϰāĻš āĻ•āϰāĻž

PowerShell āĻāĻ•āϟāĻŋ āĻŽā§‹āϟāĻžāĻŽā§āϟāĻŋ āϏāĻžāϧāĻžāϰāĻŖ āĻ…āĻŸā§‹āĻŽā§‡āĻļāύ āϟ⧁āϞ āϝāĻž āĻĒā§āϰāĻžāϝāĻŧāĻļāχ āĻŽā§āϝāĻžāϞāĻ“āϝāĻŧā§āϝāĻžāϰ āĻŦāĻŋāĻ•āĻžāĻļāĻ•āĻžāϰ⧀ āĻāĻŦāĻ‚ āϤāĻĨā§āϝ āύāĻŋāϰāĻžāĻĒāĻ¤ā§āϤāĻž āĻŦāĻŋāĻļ⧇āώāĻœā§āĻž āωāĻ­āϝāĻŧāχ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇āĨ¤
āĻāχ āύāĻŋāĻŦāĻ¨ā§āϧāϟāĻŋ āϤāĻĨā§āϝ āϏ⧁āϰāĻ•ā§āώāĻžāϰ āϘāϟāύāĻžāϗ⧁āϞāĻŋāϰ āĻĒā§āϰāϤāĻŋāĻ•ā§āϰāĻŋāϝāĻŧāĻž āϜāĻžāύāĻžāϤ⧇ āĻļ⧇āώ āĻĄāĻŋāĻ­āĻžāχāϏāϗ⧁āϞāĻŋ āĻĨ⧇āϕ⧇ āĻĄā§‡āϟāĻž āϏāĻ‚āĻ—ā§āϰāĻšā§‡āϰ āϜāĻ¨ā§āϝ PowerShell-āĻāϰ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻŦāĻŋāĻŦ⧇āϚāύāĻž āĻ•āϰāĻŦ⧇⧎ āĻāϟāĻŋ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āφāĻĒāύāĻžāϕ⧇ āĻāĻ•āϟāĻŋ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āϟ āϞāĻŋāĻ–āϤ⧇ āĻšāĻŦ⧇ āϝāĻž āĻļ⧇āώ āĻĄāĻŋāĻ­āĻžāχāϏ⧇ āϚāϞāĻŦ⧇ āĻāĻŦāĻ‚ āϤāĻžāϰāĻĒāϰ⧇ āĻāχ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‡āϰ āĻāĻ•āϟāĻŋ āĻŦāĻŋāĻļāĻĻ āĻŦāĻŋāĻŦāϰāĻŖ āĻĨāĻžāĻ•āĻŦ⧇āĨ¤

function CSIRT{
param($path)
if ($psversiontable.psversion.major -ge 5)
	{
	$date = Get-Date -Format dd.MM.yyyy_hh_mm
	$Computer = $env:COMPUTERNAME
	New-Item -Path $path$computer$date -ItemType 'Directory' -Force | Out-Null
	$path = "$path$computer$date"

	$process = get-ciminstance -classname win32_process | Select-Object creationdate, processname,
	processid, commandline, parentprocessid

	$netTCP = Get-NetTCPConnection | select-object creationtime, localaddress,
	localport, remoteaddress, remoteport, owningprocess, state
	
	$netUDP = Get-NetUDPEndpoint | select-object creationtime, localaddress,
	localport, remoteaddress, remoteport, owningprocess, state

	$task = get-ScheduledTask | Select-Object author, actions, triggers, state, description, taskname|
	where author -notlike '*МайĐēŅ€ĐžŅĐžŅ„Ņ‚*' | where author -ne $null |
	where author -notlike '*@%systemroot%*' | where author -notlike '*microsoft*'

	$job = Get-ScheduledJob

	$ADS =  get-item * -stream * | where stream -ne ':$Data'

	$user = quser

	$runUser = Get-ItemProperty "HKCU:SoftwareMicrosoftWindowsCurrentVersionRun"

	$runMachine =  Get-ItemProperty "HKLM:SoftwareMicrosoftWindowsCurrentVersionRun"

	$array = $process, $netTCP, $netUDP, $task, $user, $runUser, $runMachine, $job, $ADS
	$arrayName = "Processes", "TCPConnect", "UDPConnect", "TaskScheduled", "Users", "RunUser", "RunMachine",
	"ScheduledJob", "AlternativeDataStream"


	for ($w = 0; $w -lt $array.count; $w++){
		$name = $arrayName[$w]
		$array[$w] >> $path$name.txt
		}

	}

}

āĻļ⧁āϰ⧁ āĻ•āϰāϤ⧇, āĻāĻ•āϟāĻŋ āĻĢāĻžāĻ‚āĻļāύ āϤ⧈āϰāĻŋ āĻ•āϰ⧁āύ CSIRT āĻāĻ•ā§āϏāĻŸā§‡āύāĻļāύ, āϝāĻž āĻāĻ•āϟāĻŋ āϝ⧁āĻ•ā§āϤāĻŋ āĻ—ā§āϰāĻšāĻŖ āĻ•āϰāĻŦ⧇ - āĻĒā§āϰāĻžāĻĒā§āϤ āĻĄā§‡āϟāĻž āϏāĻ‚āϰāĻ•ā§āώāĻŖ āĻ•āϰāĻžāϰ āĻĒāĻĨāĨ¤ āĻŦ⧇āĻļāĻŋāϰāĻ­āĻžāĻ— cmdlets Powershell v5-āĻ āĻ•āĻžāϜ āĻ•āϰāĻžāϰ āĻ•āĻžāϰāϪ⧇, āϏāĻ āĻŋāĻ• āĻ…āĻĒāĻžāϰ⧇āĻļāύ⧇āϰ āϜāĻ¨ā§āϝ PowerShell āϏāĻ‚āĻ¸ā§āĻ•āϰāϪ⧇āϰ āĻāĻ•āϟāĻŋ āĻšā§‡āĻ• āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇āĨ¤

function CSIRT{
		
param($path)# ĐŋŅ€Đ¸ СаĐŋ҃ҁĐēĐĩ ҁĐēŅ€Đ¸ĐŋŅ‚Đ° ĐŊĐĩĐžĐąŅ…ĐžĐ´Đ¸ĐŧĐž ҃ĐēĐ°ĐˇĐ°Ņ‚ŅŒ Đ´Đ¸Ņ€ĐĩĐēŅ‚ĐžŅ€Đ¸ŅŽ Đ´ĐģŅ ŅĐžŅ…Ņ€Đ°ĐŊĐĩĐŊĐ¸Ņ
if ($psversiontable.psversion.major -ge 5)

āϤ⧈āϰāĻŋ āĻ•āϰāĻž āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡ āύ⧇āĻ­āĻŋāϗ⧇āĻļāύ āϏāĻšāϜ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āĻĻ⧁āϟāĻŋ āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āĻļ⧁āϰ⧁ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇: $date āĻāĻŦāĻ‚ $Computer, āϝāĻž āĻ•āĻŽā§āĻĒāĻŋāωāϟāĻžāϰ⧇āϰ āύāĻžāĻŽ āĻāĻŦāĻ‚ āĻŦāĻ°ā§āϤāĻŽāĻžāύ āϤāĻžāϰāĻŋāĻ– āύāĻŋāĻ°ā§āϧāĻžāϰāĻŖ āĻ•āϰāĻž āĻšāĻŦ⧇āĨ¤

$date = Get-Date -Format dd.MM.yyyy_hh_mm
$Computer = $env:COMPUTERNAME
New-Item -Path $path$computer$date –ItemType 'Directory' -Force | Out-Null 
$path = "$path$computer$date"

āφāĻŽāϰāĻž āĻŦāĻ°ā§āϤāĻŽāĻžāύ āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āϰ āĻĒāĻ•ā§āώ āĻĨ⧇āϕ⧇ āϚāϞāĻŽāĻžāύ āĻĒā§āϰāĻ•ā§āϰāĻŋāϝāĻŧāĻžāϗ⧁āϞāĻŋāϰ āϤāĻžāϞāĻŋāĻ•āĻžāϟāĻŋ āύāĻŋāĻŽā§āύāϰ⧂āĻĒ āĻĒāĻžāχ: $process āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞāϟāĻŋāϕ⧇ win32_process āĻ•ā§āϞāĻžāϏ⧇āϰ āϏāĻžāĻĨ⧇ get-ciminstance cmdlet āĻŦāϰāĻžāĻĻā§āĻĻ āĻ•āϰ⧇ āϤ⧈āϰāĻŋ āĻ•āϰ⧁āύāĨ¤ āϏāĻŋāϞ⧇āĻ•ā§āϟ-āĻ…āĻŦāĻœā§‡āĻ•ā§āϟ āϏāĻŋāĻāĻŽāĻĄāĻŋāϞ⧇āϟ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇, āφāĻĒāύāĻŋ āĻ…āϤāĻŋāϰāĻŋāĻ•ā§āϤ āφāωāϟāĻĒ⧁āϟ āĻĒā§āϝāĻžāϰāĻžāĻŽāĻŋāϟāĻžāϰ āϝ⧋āĻ— āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύ, āφāĻŽāĻžāĻĻ⧇āϰ āĻ•ā§āώ⧇āĻ¤ā§āϰ⧇, āĻāϗ⧁āϞāĻŋ āĻšāĻŦ⧇ āĻĒā§āϝāĻžāϰ⧇āĻ¨ā§āϟāĻĒā§āϰāϏ⧇āϏāĻŋāĻĄ (āĻĒāĻŋāĻĒāĻŋāφāχāĻĄāĻŋ āĻĒā§āϝāĻžāϰ⧇āĻ¨ā§āϟ āĻĒā§āϰāϏ⧇āϏ āφāχāĻĄāĻŋ), āĻ•ā§āϰāĻŋāϝāĻŧ⧇āĻļāύ āĻĄā§‡āϟ (āĻĒā§āϰāϏ⧇āϏ āϤ⧈āϰāĻŋāϰ āϤāĻžāϰāĻŋāĻ–), āĻĒā§āϰāϏ⧇āϏāĻĄ (āĻĒāĻŋāφāχāĻĄāĻŋ āĻĒā§āϰāϏ⧇āϏ āφāχāĻĄāĻŋ), āĻĒā§āϰāϏ⧇āϏāύ⧇āĻŽ (āĻĒā§āϰāϏ⧇āϏ āύ⧇āĻŽ), āĻ•āĻŽāĻžāĻ¨ā§āĻĄāϞāĻžāχāύāĨ¤ (āĻ¸ā§āϟāĻžāĻ°ā§āϟ āĻ•āĻŽāĻžāĻ¨ā§āĻĄ)āĨ¤

$process = get-ciminstance -classname win32_process | Select-Object creationdate, processname, processid, commandline, parentprocessid

āϏāĻŽāĻ¸ā§āϤ TCP āĻāĻŦāĻ‚ UDP āϏāĻ‚āϝ⧋āϗ⧇āϰ āĻāĻ•āϟāĻŋ āϤāĻžāϞāĻŋāĻ•āĻž āĻĒ⧇āϤ⧇, $netTCP āĻāĻŦāĻ‚ $netUDP āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞāϗ⧁āϞāĻŋāϕ⧇ āϝāĻĨāĻžāĻ•ā§āϰāĻŽā§‡ Get-NetTCPConnection āĻāĻŦāĻ‚ Get-NetTCPConnection cmdlets āĻŦāϰāĻžāĻĻā§āĻĻ āĻ•āϰ⧇ āϤ⧈āϰāĻŋ āĻ•āϰ⧁āύāĨ¤

$netTCP = Get-NetTCPConnection | select-object creationtime, localaddress, localport, remoteaddress, remoteport, owningprocess, state

$netUDP = Get-NetUDPEndpoint | select-object creationtime, localaddress, localport, remoteaddress, remoteport, owningprocess, state

āύāĻŋāĻ°ā§āϧāĻžāϰāĻŋāϤ āĻ•āĻžāϜ āĻāĻŦāĻ‚ āĻ•āĻžāĻœā§‡āϰ āϤāĻžāϞāĻŋāĻ•āĻž āϜāĻžāύāĻž āϗ⧁āϰ⧁āĻ¤ā§āĻŦāĻĒā§‚āĻ°ā§āĻŖ āĻšāĻŦ⧇āĨ¤ āĻāϟāĻŋ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āφāĻŽāϰāĻž get-ScheduledTask āĻāĻŦāĻ‚ Get-ScheduledJob cmdlets āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŋāĨ¤ āϚāϞ⧁āύ āϤāĻžāĻĻ⧇āϰ āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āύāĻŋāĻ°ā§āϧāĻžāϰāĻŖ āĻ•āϰāĻž āϝāĻžāĻ• $task āĻāĻŦāĻ‚ $job, āĻ•āĻžāϰāĻŖ āĻĒā§āϰāĻžāĻĨāĻŽāĻŋāĻ•āĻ­āĻžāĻŦ⧇, āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āĻ…āύ⧇āĻ•āϗ⧁āϞāĻŋ āύāĻŋāĻ°ā§āϧāĻžāϰāĻŋāϤ āĻ•āĻžāϜ āϰāϝāĻŧ⧇āϛ⧇, āϤāĻžāϰāĻĒāϰ⧇ āĻĻā§‚āώāĻŋāϤ āĻ•āĻžāĻ°ā§āϝāĻ•āϞāĻžāĻĒ āϏāύāĻžāĻ•ā§āϤ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āĻŦ⧈āϧ āύāĻŋāĻ°ā§āϧāĻžāϰāĻŋāϤ āĻ•āĻžāϜāϗ⧁āϞāĻŋ āĻĢāĻŋāĻ˛ā§āϟāĻžāϰ āĻ•āϰāĻž āĻŽā§‚āĻ˛ā§āϝāĻŦāĻžāύāĨ¤ āϏāĻŋāϞ⧇āĻ•ā§āϟ-āĻ…āĻŦāĻœā§‡āĻ•ā§āϟ cmdlet āφāĻŽāĻžāĻĻ⧇āϰ āĻāϤ⧇ āϏāĻžāĻšāĻžāĻ¯ā§āϝ āĻ•āϰāĻŦ⧇āĨ¤

$task = get-ScheduledTask | Select-Object author, actions, triggers, state, description, taskname| where author -notlike '*МайĐēŅ€ĐžŅĐžŅ„Ņ‚*' | where author -ne $null | where author -notlike '*@%systemroot%*' | where author -notlike '*microsoft*' # $task Đ¸ŅĐēĐģŅŽŅ‡Đ°ĐĩŅ‚ Đ°Đ˛Ņ‚ĐžŅ€ĐžĐ˛, ŅĐžĐ´ĐĩŅ€ĐļĐ°Ņ‰Đ¸Ņ… “МайĐēŅ€ĐžŅĐžŅ„Ņ‚â€, “Microsoft”, “*@%systemroot%*”, а Ņ‚Đ°ĐēĐļĐĩ ÂĢĐŋŅƒŅŅ‚Ņ‹Ņ…Âģ Đ°Đ˛Ņ‚ĐžŅ€ĐžĐ˛
$job = Get-ScheduledJob

āĻāύāϟāĻŋāĻāĻĢāĻāϏ āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡, āĻŦāĻŋāĻ•āĻ˛ā§āĻĒ āĻĄā§‡āϟāĻž āĻ¸ā§āĻŸā§āϰ⧀āĻŽ (āĻ…āĻ˛ā§āϟāĻžāϰāύ⧇āϟ āĻĄā§‡āϟāĻž āĻ¸ā§āĻŸā§āϰāĻŋāĻŽ, āĻāĻĄāĻŋāĻāϏ) āĻšāĻŋāϏāĻžāĻŦ⧇ āĻāĻ•āϟāĻŋ āϜāĻŋāύāĻŋāϏ āϰāϝāĻŧ⧇āϛ⧇āĨ¤ āĻāϰ āĻŽāĻžāύ⧇ āĻšāϞ āϝ⧇ NTFS-āĻ āĻāĻ•āϟāĻŋ āĻĢāĻžāχāϞāϕ⧇ āχāĻšā§āĻ›āĻžāĻ•ā§ƒāϤ āφāĻ•āĻžāϰ⧇āϰ āĻāĻ•āĻžāϧāĻŋāĻ• āĻĄā§‡āϟāĻž āĻ¸ā§āĻŸā§āϰāĻŋāĻŽā§‡āϰ āϏāĻžāĻĨ⧇ āφāϰāĻ“ āϝ⧁āĻ•ā§āϤ āĻ•āϰāĻž āϝ⧇āϤ⧇ āĻĒāĻžāϰ⧇āĨ¤ ADS āĻāϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡, āφāĻĒāύāĻŋ āĻāĻŽāύ āĻĄā§‡āϟāĻž āϞ⧁āĻ•āĻžāϤ⧇ āĻĒāĻžāϰ⧇āύ āϝāĻž āĻ¸ā§āĻŸā§āϝāĻžāĻ¨ā§āĻĄāĻžāĻ°ā§āĻĄ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻšā§‡āĻ• āĻĻā§āĻŦāĻžāϰāĻž āĻĻ⧃āĻļā§āϝāĻŽāĻžāύ āĻšāĻŦ⧇ āύāĻžāĨ¤ āĻāϟāĻŋ āĻĻā§‚āώāĻŋāϤ āϕ⧋āĻĄ āχāύāĻœā§‡āĻ•ā§āϟ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇ āĻāĻŦāĻ‚/āĻ…āĻĨāĻŦāĻž āĻĄā§‡āϟāĻž āϞ⧁āĻ•āĻžāϤ⧇ āĻĒāĻžāϰ⧇āĨ¤

āĻĒāĻžāĻ“āϝāĻŧāĻžāϰāĻļ⧇āϞ⧇ āĻŦāĻŋāĻ•āĻ˛ā§āĻĒ āĻĄā§‡āϟāĻž āĻ¸ā§āĻŸā§āϰāĻŋāĻŽ āĻĒā§āϰāĻĻāĻ°ā§āĻļāύ āĻ•āϰāϤ⧇, āφāĻŽāϰāĻž get-item cmdlet āĻāĻŦāĻ‚ āĻŦāĻŋāĻ˛ā§āϟ-āχāύ āϟ⧁āϞ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŦāĨ¤ Windows āϏāĻŽāĻ¸ā§āϤ āϏāĻŽā§āĻ­āĻžāĻŦā§āϝ āĻ¸ā§āĻŸā§āϰāĻŋāĻŽ āĻĻ⧇āĻ–āϤ⧇ * āϚāĻŋāĻšā§āύāϟāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧁āύ, āĻāϰ āϜāĻ¨ā§āϝ āφāĻŽāϰāĻž $ADS āύāĻžāĻŽā§‡ āĻāĻ•āϟāĻŋ āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āϤ⧈āϰāĻŋ āĻ•āϰāĻŦāĨ¤

$ADS = get-item * -stream * | where stream –ne ':$Data' 

āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āϞāĻ— āχāύ āĻ•āϰāĻž āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āĻĻ⧇āϰ āϤāĻžāϞāĻŋāĻ•āĻž āϜāĻžāύāĻžāϰ āϜāĻ¨ā§āϝ āĻāϟāĻŋ āωāĻĒāϝ⧋āĻ—ā§€ āĻšāĻŦ⧇, āĻāϰ āϜāĻ¨ā§āϝ āφāĻŽāϰāĻž āĻāĻ•āϟāĻŋ $user āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āϤ⧈āϰāĻŋ āĻ•āϰāĻŦ āĻāĻŦāĻ‚ āĻāϟāĻŋāϤ⧇ quser āĻĒā§āϰ⧋āĻ—ā§āϰāĻžāĻŽā§‡āϰ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāĻļāύ āύāĻŋāĻ°ā§āϧāĻžāϰāĻŖ āĻ•āϰāĻŦāĨ¤

$user = quser

āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āĻĒāĻž āϰāĻžāĻ–āĻžāϰ āϜāĻ¨ā§āϝ, āφāĻ•ā§āϰāĻŽāĻŖāĻ•āĻžāϰ⧀āϰāĻž āĻ…āĻŸā§‹āϰāĻžāύ⧇ āĻĒāϰāĻŋāĻŦāĻ°ā§āϤāύ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āĨ¤ āĻ…āĻŸā§‹āĻĒā§āϞ⧇āϤ⧇ āφāχāĻŸā§‡āĻŽāϗ⧁āϞāĻŋ āĻĻ⧇āĻ–āϤ⧇ āφāĻĒāύāĻŋ Get-ItemProperty cmdlet āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύāĨ¤
āφāϏ⧁āύ āĻĻ⧁āϟāĻŋ āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āϤ⧈āϰāĻŋ āĻ•āϰāĻŋ: $runUser - āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āϰ āĻĒāĻ•ā§āώ⧇ āĻ…āĻŸā§‹āϞ⧋āĻĄ āĻĻ⧇āĻ–āϤ⧇ āĻāĻŦāĻ‚ $runMachine - āĻ•āĻŽā§āĻĒāĻŋāωāϟāĻžāϰ⧇āϰ āĻĒāĻ•ā§āώ⧇ āĻ…āĻŸā§‹āϞ⧋āĻĄ āĻĻ⧇āĻ–āϤ⧇āĨ¤

$runUser = Get-ItemProperty 
"HKCU:SoftwareMicrosoftWindowsCurrentVersionRun"
$runMachine = Get-ItemProperty 
"HKLM:SoftwareMicrosoftWindowsCurrentVersionRun"

āϏāĻŽāĻ¸ā§āϤ āϤāĻĨā§āϝ āĻŦāĻŋāĻ­āĻŋāĻ¨ā§āύ āĻĢāĻžāχāϞ⧇ āϞ⧇āĻ–āĻžāϰ āϜāĻ¨ā§āϝ, āφāĻŽāϰāĻž āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āϏāĻš āĻāĻ•āϟāĻŋ āĻ…ā§āϝāĻžāϰ⧇ āĻāĻŦāĻ‚ āĻĢāĻžāχāϞ⧇āϰ āύāĻžāĻŽ āϏāĻš āĻāĻ•āϟāĻŋ āĻ…ā§āϝāĻžāϰ⧇ āϤ⧈āϰāĻŋ āĻ•āϰāĻŋāĨ¤


$array = $process, $netTCP, $netUDP, $task, $user, $runUser, $runMachine, $job, $ADS
$arrayName = "Processes", "TCPConnect", "UDPConnect" "TaskScheduled", "Users", "RunUser", "RunMachine",
"ScheduledJob", "Alternative Data Stream"

āĻāĻŦāĻ‚, āĻāĻ•āϟāĻŋ āϞ⧁āĻĒ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇, āĻĢāϞāĻ¸ā§āĻŦāϰ⧂āĻĒ āĻĄā§‡āϟāĻž āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϤ⧇ āϞ⧇āĻ–āĻž āĻšāĻŦ⧇āĨ¤

for ($w = 0; $w -lt $array.count; $w++){
	$name = $arrayName[$w]
	$array[$w] >> $path$name.txt

āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āϟāϟāĻŋ āĻ•āĻžāĻ°ā§āϝāĻ•āϰ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āϤāĻĨā§āϝ āϏāĻš 9āϟāĻŋ āĻĒāĻžāĻ ā§āϝ āĻĢāĻžāχāϞ āϤ⧈āϰāĻŋ āĻ•āϰāĻž āĻšāĻŦ⧇āĨ¤

āφāϜ, āϏāĻžāχāĻŦāĻžāϰ āύāĻŋāϰāĻžāĻĒāĻ¤ā§āϤāĻž āĻĒ⧇āĻļāĻžāĻĻāĻžāϰāϰāĻž āϤāĻžāĻĻ⧇āϰ āĻ•āĻžāĻœā§‡āϰ āĻŦāĻŋāĻ­āĻŋāĻ¨ā§āύ āĻ•āĻžāĻœā§‡āϰ āϏāĻŽāĻžāϧāĻžāύ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āϤāĻĨā§āϝ āϏāĻŽā§ƒāĻĻā§āϧ āĻ•āϰāϤ⧇ PowerShell āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύāĨ¤ āĻ…āĻŸā§‹āϞ⧋āĻĄ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āĻāĻ•āϟāĻŋ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āϟ āϝ⧋āĻ— āĻ•āϰ⧇, āφāĻĒāύāĻŋ āĻĄāĻžāĻŽā§āĻĒāĻŋāĻ‚, āĻ›āĻŦāĻŋ āχāĻ¤ā§āϝāĻžāĻĻāĻŋ āĻ›āĻžāĻĄāĻŧāĻžāχ āĻ•āĻŋāϛ⧁ āϤāĻĨā§āϝ āĻĒ⧇āϤ⧇ āĻĒāĻžāϰ⧇āύāĨ¤

āωāĻ¤ā§āϏ: www.habr.com

DDoS āϏ⧁āϰāĻ•ā§āώāĻž, VPS VDS āϏāĻžāĻ°ā§āĻ­āĻžāϰ āϏāĻš āϏāĻžāχāϟāϗ⧁āϞāĻŋāϰ āϜāĻ¨ā§āϝ āύāĻŋāĻ°ā§āĻ­āϰāϝ⧋āĻ—ā§āϝ āĻšā§‹āĻ¸ā§āϟāĻŋāĻ‚ āĻ•āĻŋāύ⧁āύ đŸ”Ĩ DDoS āϏ⧁āϰāĻ•ā§āώāĻž āϏāĻš āύāĻŋāĻ°ā§āĻ­āϰāϝ⧋āĻ—ā§āϝ āĻ“āϝāĻŧ⧇āĻŦāϏāĻžāχāϟ āĻšā§‹āĻ¸ā§āϟāĻŋāĻ‚ āĻ•āĻŋāύ⧁āύ, VPS VDS āϏāĻžāĻ°ā§āĻ­āĻžāϰ | ProHoster