nexxai / CryptoBlocker

A script to deploy File Server Resource Manager and associated scripts to block infected users
GNU General Public License v2.0
200 stars 73 forks source link

Directory Exception #50

Closed Rooven-tech closed 6 years ago

Rooven-tech commented 6 years ago

Hi,

I could not see if this has been answered anywhere but FSRM is passive on C:\, C:\Windows\system. We are monitoring Event Viewer for 8215 errors to create alerts through Automate. We get alerts for C:\Windows\WinSxS\Temp\PendingDeletes\a9eb206dedf6d2017c0400006882a480.icrav03.rat. Wanted to Exception this folder or c:\windows\winsxs\temp\ from any monitoring. Please let me know how anyone has done this