Closed chrisanag1985 closed 8 months ago
Hi - echo is a shell built-in in most circumstances:
$ type echo echo is a shell builtin
If you were to specifically run the echo binary (/usr/bin/echo) Sysmon will fire a ProcessCreate event.
Thanks for the clarification. So the bash doesn't use the /usr/bin/echo, but the built-in command. Thank you for your reply.
Hi!!! As Sysmon For Linux doesn't support File Integrity, i am trying to create rules that have to do with editing a file under linux filesystem, like
echo "test" > file.txt || echo "test" >> file.txt
. But theProcessCreate
doesn't print these commands. I know that some commands likehistory, unset
are not real commands(binaries), butecho
command has a binary file. Is a problem of Sysmon or i do something wrong? Thanks in advance