Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sysmonconfig-research.xml configuration block, delete exe file #151

Open
webdevbeginner opened this issue Nov 1, 2022 · 0 comments
Open

Comments

@webdevbeginner
Copy link

I am running sysmon with sysmonconfig-research.xml configuration on 2 machines. Currently a machine is still running normally, but one machine blocks most exe files, blocks windows updates, downloads exe files, even deletes files when opening properties. I looked at the log and saw a lot of event id 27. I turned off sysmon and the problem was solved. Could this be the cause of the problem? I wonder because sysmon only blocks but why is the file even deleted when viewing properties

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant