监听相关事件:# 监控可疑的VHD挂载与后续PowerShell活动# 需要管理员权限运行$Query = @"<QueryList><Query Id="0" Path="Microsoft-Windows-<em>DiskManagement</em>-API "><Select Path="Microsoft-Windows-<em>DiskManagement</em>-API">*[System[EventID=2]]</Select><!
--- Control Name: Disk Management Snap-In Object Library Version: 1.0 Status: Registered ProgID: DiskManagement.Control