- Apr 25, 2015
- 1,845
- 2
- 2,199
- 327
Let's run through a sample case, we get a process list from system 1:
Then how about we get unique files:
So now we have a tasks file to open in Excel.
Insert just above, like so:
data:image/s3,"s3://crabby-images/520d2/520d234220c1d05ef83f2d1869f0bb9c667dfe4a" alt="1576789449906.png 1576789449906.png"
Time to add server names and highlight AN ENTIRE LIST to format.. for example click "B" so the FULL_FUCKING_ENTIRE_COLUMN is selected (not like my picture shows):
data:image/s3,"s3://crabby-images/4e45e/4e45ee8135190e4cacec2498bcfd31658c8d5f62" alt="1576789630336.png 1576789630336.png"
Click on "Home > Conditional Formatting > New Rule..."
Select "Use a formula to determine which cells to format"
Now enter this:
Select a format to apply, for example I select Fill > select blue color for the font text color.
data:image/s3,"s3://crabby-images/0a8d5/0a8d5817da0d72c0635b4261d45bc6ff0010ccfc" alt="1576789758320.png 1576789758320.png"
...
data:image/s3,"s3://crabby-images/59ae9/59ae91f96749b0da70d084a571aa87822e83c143" alt="1576789909884.png 1576789909884.png"
Now you can see, side-by-side comparison of known files versus unknown files.
Imagine doing this with file hashes, we will come back around to that another time.
Code:
Get-Process | Select-Object Path | sort | findstr ".exe" > C:\running.txt
Then how about we get unique files:
Code:
gc .\running.txt | gu > tasks.csv
So now we have a tasks file to open in Excel.
Insert just above, like so:
data:image/s3,"s3://crabby-images/520d2/520d234220c1d05ef83f2d1869f0bb9c667dfe4a" alt="1576789449906.png 1576789449906.png"
Time to add server names and highlight AN ENTIRE LIST to format.. for example click "B" so the FULL_FUCKING_ENTIRE_COLUMN is selected (not like my picture shows):
data:image/s3,"s3://crabby-images/4e45e/4e45ee8135190e4cacec2498bcfd31658c8d5f62" alt="1576789630336.png 1576789630336.png"
Click on "Home > Conditional Formatting > New Rule..."
Select "Use a formula to determine which cells to format"
Now enter this:
Code:
=countif($A:$A, $B1)
Select a format to apply, for example I select Fill > select blue color for the font text color.
data:image/s3,"s3://crabby-images/0a8d5/0a8d5817da0d72c0635b4261d45bc6ff0010ccfc" alt="1576789758320.png 1576789758320.png"
...
data:image/s3,"s3://crabby-images/59ae9/59ae91f96749b0da70d084a571aa87822e83c143" alt="1576789909884.png 1576789909884.png"
Now you can see, side-by-side comparison of known files versus unknown files.
Imagine doing this with file hashes, we will come back around to that another time.