|
1 | 1 | #Requires -Version 7.0
|
2 | 2 |
|
3 | 3 | <#
|
4 |
| - .SYNOPSIS |
5 |
| - A brief description of the EvtxECmdGapFinder.ps1 file. |
6 |
| - |
7 | 4 | .DESCRIPTION
|
8 | 5 | A script to identify time gaps in EvtxECmd CSV output. This can be useful for identifying potential remediation on a host.
|
9 | 6 |
|
@@ -121,8 +118,8 @@ foreach ($csvFile in $csvFiles)
|
121 | 118 | # SIG # Begin signature block
|
122 | 119 | # MIIvngYJKoZIhvcNAQcCoIIvjzCCL4sCAQExDzANBglghkgBZQMEAgEFADB5Bgor
|
123 | 120 | # BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG
|
124 |
| -# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCALKyD+oLwyyzD7 |
125 |
| -# eCLCTXNAVC8sJAJQL9f8o+QghXn8oaCCKKMwggQyMIIDGqADAgECAgEBMA0GCSqG |
| 121 | +# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCB/yZwG1Fc/Zo58 |
| 122 | +# iMk6Hew7Eq9NL/jNDLynTi2qapKhaKCCKKMwggQyMIIDGqADAgECAgEBMA0GCSqG |
126 | 123 | # SIb3DQEBBQUAMHsxCzAJBgNVBAYTAkdCMRswGQYDVQQIDBJHcmVhdGVyIE1hbmNo
|
127 | 124 | # ZXN0ZXIxEDAOBgNVBAcMB1NhbGZvcmQxGjAYBgNVBAoMEUNvbW9kbyBDQSBMaW1p
|
128 | 125 | # dGVkMSEwHwYDVQQDDBhBQUEgQ2VydGlmaWNhdGUgU2VydmljZXMwHhcNMDQwMTAx
|
@@ -342,36 +339,36 @@ foreach ($csvFile in $csvFiles)
|
342 | 339 | # 9lAXRaV/0x/qHtrv6DGCBlEwggZNAgEBMGgwVDELMAkGA1UEBhMCR0IxGDAWBgNV
|
343 | 340 | # BAoTD1NlY3RpZ28gTGltaXRlZDErMCkGA1UEAxMiU2VjdGlnbyBQdWJsaWMgQ29k
|
344 | 341 | # ZSBTaWduaW5nIENBIFIzNgIQNZ6LJbr/UQt8TtHttsJpJDANBglghkgBZQMEAgEF
|
345 |
| -# AKBMMBkGCSqGSIb3DQEJAzEMBgorBgEEAYI3AgEEMC8GCSqGSIb3DQEJBDEiBCAY |
346 |
| -# Zd7zOxrhgT2wS1Luf078KyFy59nr2iIavWHC7KfUpTANBgkqhkiG9w0BAQEFAASC |
347 |
| -# AgA3GCvOsQmNnggqR9nNhLldDrztKu9st/KT8KdNoQfsNU7XLnr015/MHcRgRnHB |
348 |
| -# 7U6Mf+Iti8BBrO3xAKnqewbPygoGB5CCILqL8VAI+oXej6v3M+veOLe7H1BVb8cO |
349 |
| -# GkItKzELPH9YBIpuKYQ7vfRXBtKrsa4lYVq9SwvG05/AIXX+OKuFfhIpUwzoZfjr |
350 |
| -# i6fkgriC03x1TbURIfS24R/Wjqs8NXcLMJeI4Uu/pJtkRI03LIXZoOJXXh7v6Zbo |
351 |
| -# PRl6jGSVobkR+NlccZVicWh+AmvIv1y0ABDwex403CPLTYAiu5TnFgdCrFplve2r |
352 |
| -# QKVNubX4fVPpk07eobI5tYoOmfnMP/QzNEAD5I/id43cU3Ga/sn1Wjlmh2EfGD7h |
353 |
| -# EY50kv1nO054MYBJUWAxQRjaILV7MqMzJheBJkWusVdSAZRW+M0z4/mSTZNApHEd |
354 |
| -# J03Jwvpc1dCpOJe9ij29hqnnWn5EYHssjua5ZiZRe2B1DWhfdp1SnEpIiF0als5/ |
355 |
| -# 35RENnJgvajax/AuqQhPsd1uDXIP9bToh3ca4VYJJDNG/IZbDmwoJCh/sHZ+vExN |
356 |
| -# 1YpTUqUKpWSMaWReLAYfP0diLagI8h6WU70ZOA6IaCkmijXk3bEHmV/fm1S4LO8/ |
357 |
| -# aIBBxrqEPEVE1GFdEiWE0L8YjIs6nL25jd2O4vUG8ca05qGCA2wwggNoBgkqhkiG |
| 342 | +# AKBMMBkGCSqGSIb3DQEJAzEMBgorBgEEAYI3AgEEMC8GCSqGSIb3DQEJBDEiBCAO |
| 343 | +# GNsPhUX+zDiJ09tLs23oZ3uBCqnUQdEvO3IhQpDNYDANBgkqhkiG9w0BAQEFAASC |
| 344 | +# AgBGhizi9OrUH24/xIYV4hmHH7/T/Rq39N0/+6Q2DmcW7NMTyck5107vyHnkbXKA |
| 345 | +# SfzoIaP9t7Z2ud2hxBBRxSvTZl90qmPozOTRf93WWIwtl0UiE9GcY7nF2gZ70bPc |
| 346 | +# Ygyqf5iLL56qCAofRqJlq3ojuSPvx+3zNB5upS2RumBCOCNp3GkQoKVcaIfdfipG |
| 347 | +# yhzhaT84vOg06h974hjn139iWrZ6/hE/Zx0NzhEAjh4hqM3yCbyBTEpoOfqY/5Kf |
| 348 | +# MTFDG/ni1Tsrqj9Emx/hZRw2LRNMG2L1sTohrgsvZkCVBrjfVJVAnlvubQMuo19q |
| 349 | +# b4dR3pZgoltE9DIxwPSheTQE/SRyNih3jB/ZEWpzIS+D45dteAaLLTMPKev1a/ZP |
| 350 | +# IrvxRMCNVSUYSzR9XpJ0HLVNwByedbWUgSkHq7QRrOzTyUlfdJ5YIDGQbk0SokQP |
| 351 | +# My01xWcvI/q/1QOXO2FDloUQvfe3ZTN7s1C+ho110o/aD0/68ZvApP+R2qCifE6m |
| 352 | +# sGUni8SXZhxkzMLI+5SMD5eFnH109HiKKvqdtFSQmEYYHVP/O8CEd0TVqgTDtaC/ |
| 353 | +# oVUmHoVj2v6508JdcKg3cD8BjIKRNL23khtBirUqKSRwk+tUkbZK6UwUmGgxPwWB |
| 354 | +# 4rA+nSOLJ1glMagy4RqbMInysyRGttq82Uq8rlKd0WQ8YaGCA2wwggNoBgkqhkiG |
358 | 355 | # 9w0BCQYxggNZMIIDVQIBATBvMFsxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i
|
359 | 356 | # YWxTaWduIG52LXNhMTEwLwYDVQQDEyhHbG9iYWxTaWduIFRpbWVzdGFtcGluZyBD
|
360 | 357 | # QSAtIFNIQTM4NCAtIEc0AhABB2SbCLCn/n3WVKjy9Cn2MAsGCWCGSAFlAwQCAaCC
|
361 | 358 | # AT0wGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUxDxcNMjQw
|
362 |
| -# NzI2MDI1NzEyWjArBgkqhkiG9w0BCTQxHjAcMAsGCWCGSAFlAwQCAaENBgkqhkiG |
363 |
| -# 9w0BAQsFADAvBgkqhkiG9w0BCQQxIgQgTrc2VhE/xBQczMdgTHCDACSJuFzpC+x1 |
364 |
| -# LIdryZEtUAwwgaQGCyqGSIb3DQEJEAIMMYGUMIGRMIGOMIGLBBRE05OczRuIf4Z6 |
| 359 | +# NzI2MDMwMDA0WjArBgkqhkiG9w0BCTQxHjAcMAsGCWCGSAFlAwQCAaENBgkqhkiG |
| 360 | +# 9w0BAQsFADAvBgkqhkiG9w0BCQQxIgQg2Qsict3neLfRi3XMyZ8vtofoiYPy+kYz |
| 361 | +# 3JbSh56x8MgwgaQGCyqGSIb3DQEJEAIMMYGUMIGRMIGOMIGLBBRE05OczRuIf4Z6 |
365 | 362 | # zNqB7K8PZfzSWTBzMF+kXTBbMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQR2xvYmFs
|
366 | 363 | # U2lnbiBudi1zYTExMC8GA1UEAxMoR2xvYmFsU2lnbiBUaW1lc3RhbXBpbmcgQ0Eg
|
367 | 364 | # LSBTSEEzODQgLSBHNAIQAQdkmwiwp/591lSo8vQp9jANBgkqhkiG9w0BAQsFAASC
|
368 |
| -# AYCPGF1vKV72p3g+eykFLGG5c3U2Nf3Ex4VSRgoZBzsVXCXAuIRYSFfmnOE/9xC+ |
369 |
| -# kYSLWINRyf1goe1wYrEqTQIgsqp24Hfuk87YYMcWeVk6TN10DHB/fmkxWEVGTYRD |
370 |
| -# +KPR3DcUxlpN6hcqBD80Zzk1iOjwu+m4BOxTIy8FqD4agDp9Wz/LazO1A/cgfJb/ |
371 |
| -# RJcT8gX/N9zSOnyQthcC8/G+uXr0AdaUglmP2Gs7yT91r++wsRDQ4dvQTpVFU1lO |
372 |
| -# 0Bfn15T1xDwBdUyQzmSIuXH9sAQ7gfn4nXb9aYjfqYHl8CYWgwQIcF1rlOZjmz1l |
373 |
| -# V0nLxGNc7HyU5EIZE70DGpLuLcLBMjrjGNu3zrqsNqRuHp0drF4Yb2//BDTxPfG5 |
374 |
| -# VhISQarbdAzLCNLN7NB68M4WuHsPZDoWs76RNfEQCIqV6dNTfNyi1ijQv/mIHPlI |
375 |
| -# OlnS2vLNq1p57nydtyLhoR4bkTVYxeJMhznDrz00PK3opaVNGofQOAH9Lhv2f+tJ |
376 |
| -# Tzg= |
| 365 | +# AYCs5fDpDOLJaOzc+P1EQDLPAtQ995/l5xqG9R6DcdOV72Mq7w0BUWVCPApWo9e9 |
| 366 | +# XG/9V+gg9gqrVtul5Tvb2t4hvJgI5/aRuSFqaZO3sGSb5vOMIjmCjq26ZdN6vmNP |
| 367 | +# cQ8ubGL8Pnn4v+Vy4de9Ot150d5D5Mzf6q7hdDYdzykD90IgJWkAxoDgOeExyG5C |
| 368 | +# cl3THG3MG+xYyvGw6MfFp/QZ1KMBfN1o4+IiR60wQ1gET0WSC0Lnu38TgO6yrj7J |
| 369 | +# xE4akHTJ8VXSmsfY0F+h9e0Gxb2dO3STaV833uXj24Br7CXjgUnXYkNHd4bOZvT5 |
| 370 | +# aJBvJe8BCNCkIlfIhMb83z/hC1J8+6zHNNGCE56bjf6zwbvtZ7iXd0UkhfF7hiwA |
| 371 | +# i7SmWewiMR+E8wHwMnzRMCfnScGqCbY3XgityWsuX6JJ9WDqqBlKZfSrJJrrIDco |
| 372 | +# LzSePVwiCQr7kgWV/G2/YDB9fBM62Pxr20r8zherjfh9da1elobrsVh3Pg6hpC4A |
| 373 | +# pAM= |
377 | 374 | # SIG # End signature block
|
0 commit comments