olafhartong / sysmon-modular

A repository of sysmon configuration modules
MIT License
2.66k stars 589 forks source link

Create 23 exclusion for Sophos Endpoint journalling temporary files #169

Closed jaybirnuw closed 1 year ago

jaybirnuw commented 1 year ago

This exclusion for file deletions corrects a conflict between security log journalling performed by Sophos and Sysmon. This was created from documentation found at https://support.sophos.com/support/s/article/KB-000044827?language=en_US.

olafhartong commented 1 year ago

thank you!