|
|
|
@ -373,4 +373,12 @@ I first wanted to see how powershell called the command, so i looked through the
|
|
|
|
|
Get-Command Set-MpPreference | fl
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
If we wanted to read the MSFT_MpPreference class, it is documented here:
|
|
|
|
|
https://docs.microsoft.com/en-us/previous-versions/windows/desktop/legacy/dn455323(v=vs.85)#requirements
|
|
|
|
|
We can access via powershell like so:
|
|
|
|
|
```
|
|
|
|
|
Get-WmiObject -ClassName MSFT_MpPreference -Namespace root/microsoft/windows/defender
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|