Sysinternals Blog

Options
393
MarkRussinovich on Jun 27 2019 11:58 AM
312
MarkRussinovich on Jun 27 2019 11:57 AM
221
MarkRussinovich on Jun 27 2019 11:56 AM
1,400
MarkRussinovich on Jun 27 2019 11:54 AM
352
MarkRussinovich on Jun 27 2019 11:54 AM
182
MarkRussinovich on Jun 27 2019 11:54 AM
303
MarkRussinovich on Jun 27 2019 11:49 AM

Latest Comments

in Sysmon v15.14 on May 03 2024 01:20 PM
Thanks for reporting - apparently it doesn't correctly parse those config settings. As for the service name, I'll update the docs to reflect the current functionality.
1 Likes
in Sysmon v15.14 on May 03 2024 11:29 AM
OK in the file I had on my test I box had this (A slight variation ) <Sysmon schemaversion="4.90"> <DnsLookup></DnsLookup> <DriverName>AudiusSv</DriverName> <EventFiltering> <RuleGroup name="" groupRelation="or"> <ProcessCreate onmatch="include" /> </RuleGroup> <RuleGroup name="" groupRelation="or">...
0 Likes
in Sysmon v15.14 on May 03 2024 10:58 AM
Running the above here produces the following, maybe it's of help: PS C:\remote\Sysmon> gc .\audius.xml <Sysmon schemaversion="4.90"> <DriverName>AudiusSv</DriverName> <EventFiltering> <RuleGroup name="" groupRelation="or"> <ProcessCreate onmatch="include" /> </RuleGroup> <RuleGroup name="" groupRel...
0 Likes
in Sysmon v15.14 on May 03 2024 10:48 AM
There is no error. It simply ignores the directive.Using the XLM file I posted above, if I run:Sysmon64.exe -i my_custom_noted_above.xmlthe DriverName directive in the XML is ignored.It creates a service called sysmon64 and a driver called sysmondrvThe DriverName directive is ignored.
0 Likes
in Sysmon v15.14 on May 03 2024 10:42 AM
Are you getting any error or other output from Sysmon? Do you install it with the config, or reconfigure?
0 Likes