1 2 3 4 5 6 7 8 9 |
#Ejecutar PowerShell como administrador while(1) { Get-Event | Remove-Event -ErrorAction SilentlyContinue #Registrar el evento de ejecutar notepad Register-WmiEvent -Query "SELECT * FROM Win32_ProcessStartTrace" Wait-Event -OutVariable Event | Out-Null $Event.sourceargs.newevent | select-Object ProcessName,TIME_CREATED } |