Contoh perintah respons langsung

Pelajari tentang perintah umum yang digunakan dalam respons langsung dan lihat contoh tentang bagaimana perintah tersebut biasanya digunakan.

Bergantung pada peran yang Anda miliki, Anda dapat menjalankan perintah respons langsung dasar atau tingkat lanjut. Untuk informasi selengkapnya tentang perintah dasar dan tingkat lanjut, lihat Menyelidiki entitas pada perangkat menggunakan respons langsung.

analyze

# Analyze the file malware.txt
analyze file c:\Users\user\Desktop\malware.txt
# Analyze the process by PID
analyze process 1234

connections

# List active connections in json format using parameter name
connections -output json
# List active connections in json format without parameter name
connections json

dir

# List files and sub-folders in the current folder (by default it will show relative paths [-relative_path])
dir
# List files and sub-folders in the current folder, with their full path
dir -full_path
# List files and sub-folders in a specific folder
dir C:\Users\user\Desktop\
# List files and subfolders in the current folder in json format
dir -output json

fileinfo

# Display information about a file
fileinfo C:\Windows\notepad.exe

findfile

# Find file by name
findfile test.txt

get

# Download a file from a machine
get c:\Users\user\Desktop\work.txt
# Download a file from a machine, automatically run prerequisite commands
get c:\Users\user\Desktop\work.txt -auto

Note

Jenis file berikut tidak dapat diunduh menggunakan perintah ini dari dalam Respons Langsung:

PowerShell mendukung jenis file ini.

Gunakan PowerShell sebagai alternatif, jika Anda memiliki masalah saat menggunakan perintah ini dari dalam Respons Langsung.

library

# List files in the library
library
# Delete a file from the library
library delete script.ps1

processes

# Show all processes
processes
# Get process by pid
processes 123
# Get process by pid with argument name
processes -pid 123
# Get process by name
processes -name notepad.exe

putfile

# Upload file from library
putfile get-process-by-name.ps1
# Upload file from library, overwrite file if it exists
putfile get-process-by-name.ps1 -overwrite
# Upload file from library, keep it on the machine after a restart
putfile get-process-by-name.ps1 -keep

registry

# Show information about the values in a registry key
registry HKEY_CURRENT_USER\Console
# Show information about a specific registry value (the double backslash \\ indicates a registry value versus key)
registry HKEY_CURRENT_USER\Console\\ScreenBufferSize

remediate

# Remediate file in specific path
remediate file c:\Users\user\Desktop\malware.exe
# Remediate process with specific PID
remediate process 7960
# See list of all remediated entities
remediate list

Note

Saat ini, HKEY_USERS reg hive tidak didukung untuk remediate. Ini adalah masalah yang diketahui, dan kami sedang mencarinya.

run

# Run PowerShell script from the library without arguments
run script.ps1
# Run PowerShell script from the library with arguments
run get-process-by-name.ps1 -parameters "-processName Registry"

Note

Untuk perintah jangka panjang seperti 'run' atau 'getfile', Anda mungkin ingin menggunakan simbol '&' di akhir perintah untuk melakukan tindakan tersebut di latar belakang. Jika Anda menggunakan simbol 'g', Anda dapat terus menyelidiki mesin dan kembali ke perintah latar belakang ketika selesai menggunakan perintah dasar 'fg'.

Saat meneruskan parameter ke skrip respons langsung, jangan sertakan karakter terlarang berikut: ';', '&', '|', '!', dan '$'.

scheduledtask

# Get all scheduled tasks
scheduledtasks
# Get specific scheduled task by location and name
scheduledtasks Microsoft\Windows\Subscription\LicenseAcquisition
# Get specific scheduled task by location and name with spacing
scheduledtasks "Microsoft\Configuration Manager\Configuration Manager Health Evaluation"

undo

# Restore remediated registry
undo registry HKEY_CURRENT_USER\Console\ScreenBufferSize
# Restore remediated scheduledtask
undo scheduledtask Microsoft\Windows\Subscription\LicenseAcquisition
# Restore remediated file
undo file c:\Users\user\Desktop\malware.exe