CimSweep
CimSweep copied to clipboard
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
Get-CSUsbStorageDevice queries the SYSTEM\CurrentControlSet\Enum\USBSTOR to receive the current attached USB storage devices.
According to [Enable virtualization-based protection of code integrity](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity) AvailableSecurityProperty translates to MBEC (Mode-based execution control).