olafhartong / sysmon-modular

A repository of sysmon configuration modules
MIT License
2.66k stars 589 forks source link

Update to line 163 in sysmonconfig-mde-augment.xml #158

Closed kevinelwell closed 1 year ago

kevinelwell commented 1 year ago

In the sysmonconfig-mde-augment.xml file

olafhartong commented 1 year ago

Hey Kevin, thanks for spotting this. However, this file is automatically generated from all the modules and will be overwritten every run. The correct module that needs to altered is;

https://github.com/olafhartong/sysmon-modular/blob/fa1ae53132403d262be2bbd7f17ceea7e15e8c78/1_process_creation/include_living_off_the_land.xml#L93

Please let me know whether you want to do it or if you don't care about the contribution flag. In that case I'll fix it myself.

kevinelwell commented 1 year ago

Olaf,

You are most welcome! Thank you for creating this and sharing it with folks. I created a new pull request 159.

Sent with Proton Mail secure email.

------- Original Message ------- On Thursday, December 8th, 2022 at 11:52 AM, Olaf Hartong @.***> wrote:

Hey Kevin, thanks for spotting this. However, this file is automatically generated from all the modules and will be overwritten every run. The correct module that needs to altered is;

https://github.com/olafhartong/sysmon-modular/blob/fa1ae53132403d262be2bbd7f17ceea7e15e8c78/1_process_creation/include_living_off_the_land.xml#L93

Please let me know whether you want to do it or if you don't care about the contribution flag. In that case I'll fix it myself.

— Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you authored the thread.Message ID: @.***>