Describe the bug
I'm experimenting with using sysmon to monitor builds. On Windows, I get plenty of ImageLoad events (event ID 7) when building and running a dotnet package, but I'm not getting any at all on Linux, even if I use dotnet to directly run the built .dll file. Is it expected that I wouldn't see these events on Linux?
To Reproduce
Create a new, empty c# console app with Visual Studio
Start sysmon with the config below
Using the dotnet CLI, build and run the new C# app
Open /var/log/syslog, search for "7, and observe that there are no results.
Describe the bug I'm experimenting with using sysmon to monitor builds. On Windows, I get plenty of ImageLoad events (event ID 7) when building and running a dotnet package, but I'm not getting any at all on Linux, even if I use dotnet to directly run the built .dll file. Is it expected that I wouldn't see these events on Linux?
To Reproduce
/var/log/syslog
, search for "Sysmon version v1.3.2
Distro/kernel version Ubuntu 22.04
Sysmon configuration
Logs N/A (not much to see other than a lot of events that aren't ImageLoads)
Expected behavior ImageLoad events are logged for .dlls loaded by dotnet