Thanks for reporting - apparently it doesn't correctly parse those
config settings. As for the service name, I'll update the docs to
reflect the current functionality.
OK in the file I had on my test I box had this (A slight variation )
<Sysmon schemaversion="4.90"> <DnsLookup></DnsLookup>
<DriverName>AudiusSv</DriverName> <EventFiltering> <RuleGroup name=""
groupRelation="or"> <ProcessCreate onmatch="include" /> </RuleGroup>
<RuleGroup name="" groupRelation="or">...
There is no error. It simply ignores the directive.Using the XLM file I
posted above, if I run:Sysmon64.exe -i my_custom_noted_above.xmlthe
DriverName directive in the XML is ignored.It creates a service called
sysmon64 and a driver called sysmondrvThe DriverName directive is
ignored.
Latest Comments