SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.68k stars 1.69k forks source link

Capturing deleted files #169

Open harryray33 opened 1 year ago

harryray33 commented 1 year ago

Do you, by any chance, have a config file for the sysmon ability to intercept deleted files please.

As shown in this sysinternal video https://youtu.be/_MUP4tgdM7s?t=148