SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.68k stars 1.69k forks source link

Event id 26 #153

Closed Richman711 closed 2 years ago

Richman711 commented 3 years ago

Added support for Event ID 26 which has been available since schema 4.60. By updating the schema version to the latest version (4.70) you can leverage the new event ID which is nearly identical to Event ID 23 except that it doesn't archive a copy of the file deleted. This event can be applied more widespread as there isn't risk of filling up the drive with copies of files in a poorly filtered event 23.