Closed PetrPoleshko closed 7 years ago
I had issues with Registry Exclusions not working. Had to uninstall sysmon and reinstall with the updated config.
Skizztle, If you only knew how many times i did complete uninstall of Sysmon and install it back again with Tay's config... :( FileCreateTime is not the only one which doesn't accept filter rules... RawDiskRead - doesn't filter events by ProcessGUID too...
Please try Sysmon 6.03 which should fix this issue
Hello, I installed Sysmon with your configuration file .
I receive event 11 with message like below:
I went ahead and modified lines related to FileCreate as below and I still receive eventids by MonitoringHost.exe
The question is: What's the correct form of excluding Images from FileCreate events?