Published Apr 12, 2023
Version 1.0Alex_Mihaiuc
Microsoft
Joined August 30, 2020
Sysinternals Blog
Follow this blog board to get notified when there's new activity
I wonder if there are any plans on Sysmon to have a builtin quota for ArchiveDirectory. Currently the option is either not use it via the FileDeleteDetected event or create a WMI subscription triggering a delete command.
https://gist.github.com/zbalkan/17fbe38864a900a2f1eeac2088c5d49e