re = /(?i).* msiexec.*:\\\\/m
str = 'cmd.exe msiexec.exe:\\\\ someprogram -argument "stuff"
MSI Exec Web install
SysmonEvent | where (EventID == 1 and (CommandLine matches regex @\'(?i).* msiexec.*:\\\\/\\\\/.*\'))
SecurityEvent | where (EventID == 4688 and (ProcessCommandLine matches regex @\'(?i).* msiexec.*:\\\\/\\\\/.*\'))'
# Print the match result
str.scan(re) do |match|
puts match.to_s
end
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Ruby, please visit: http://ruby-doc.org/core-2.2.0/Regexp.html