ceramicskate0 / sysmon-config

CeramicSkate0 Sysmon configuration fork file template with default high-quality event tracing
https://github.com/ceramicskate0/sysmon-config
10 stars 0 forks source link

excluide id 11 2 #67

Closed ceramicskate0 closed 2 years ago

ceramicskate0 commented 2 years ago

Image: C:\WINDOWS\Explorer.EXE ends with TargetFilename: \AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db