SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.74k stars 1.7k forks source link

Dropbox Updater #5

Closed Darkbat91 closed 7 years ago

Darkbat91 commented 7 years ago

Is the Dropbox updater considered sufficiently hardened? If so i think it would be prudent to add one of the below.

Image C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

Or Command line "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /ua /installsource scheduler

SwiftOnSecurity commented 7 years ago

Right now I'm considering how deep I want to go into whitelisting with this, I could very well accept this request. Give me some time to mull it over. Appreciate your contributions! I'm so honored! @Darkbat91

Darkbat91 commented 7 years ago

Understood, It is a complicated balance between whitelisting it so that there is not an over abundance of information and Making sure that information is not being Ignored which is important.

SwiftOnSecurity commented 7 years ago

Added in