Sysmon 12.03 not logging EventID:2 (file creation time modified)
Hello, I just made a test with Sysmon 9.1.0 on a VM and I was able to get file creation time modification events. Upgrading to 12.03 with the same configuration allows to get all the other events except this one. Test was made using a ps1 script that…
Is it safe to defragment an in-use file with Contig?
Greetings, I'm wondering if I should expect issues when running Sysinternals' Contig on an SQLite database that's concurrently being written to and read from. I think I may be running into an issue with an extremely fragmented SQLite file and I'm…
VirusTotal
Recently, the VirusTotal column always shows Unknown. What's up?
s.exe and chinese characters in sysmon log
We came across a puzzling process called s.exe and chinese characters in the logs as seen below, which we have never seen before across any system. We use sysmon version 8.4.0.0. Is this a case of the sysmon driver causing trimming of data or a bug or…
Client is not communication with MP SCCM 2012
I have installed SCCM 2012 client on one machine, installation was successful but it not communicating to MP. There are only two options(Machine policy & user policy) under action tab in configuration manage and CCM Notification Agent is also…
Autoruns looks bad in 4K
Try running Autoruns on a 4K monitor, or any other HDPI display. You will almost not be able to read the entries.
CoreInfo shows wrong output
Hello Microsoft Team, while playing with the GetLogicalProcessorInformation function and comparing the output with the coreinfo (32bit & 64bit) tool, I discovered some inconsistencies in the Cache Map output. Running on: Intel(R) Core(TM) i7-7700…
Remote Kernal Debug Mode Network
If setting up remote kernel debugging using rdnet, on the host is the network connection named 'NETWORK 20' and can be seen in the available WiFI networks? Is it not disconnectable?
Sysmon 10.42
Hello. We are using Sysmon 10.42 and faced the problem of a long launch of published applications from Citrix. We also use antivirus McAfee Endpoint Security 10.7. Sysmon has been added to exceptions, but there are suggestions that blocking occurs. …
Sysmon - not logging "Pipe created" events (Event 17)
Hello! We have tried to generate/reproduce Event 17: <event name="SYSMON_CREATE_NAMEDPIPE" value="17" level="Informational" template="Pipe Created" rulename="PipeEvent"…
Inquiry about nesting Sysmon rule groups
This is in reference to your comment on the above topic at the below link about possible support for nesting of Sysmon rule groups: https://github.com/MicrosoftDocs/sysinternals/issues/222 My particular use case is to exclude multiple classes of…
svchost.exe process details
Due to the dramatic increase in svchost and services in Windows 10, could you please create an option for a "Services" column instead of making it a hover over pop-up?
How to compile a regular expression that will search and replace characters from a string
Hello Community, I hope I'm in the right forum for this question I'm trying to compile a regular expression that will search for strings that exclude certain characters and and charaters to the discovered strings. For example, the following string…