sandboxie-plus / Sandboxie

Sandboxie Plus & Classic
https://Sandboxie-Plus.com
GNU General Public License v3.0
13.63k stars 1.51k forks source link

Add EventLog monitoring for ForceFolder / ForceProcess #4113

Open 1mm0rt41PC opened 2 months ago

1mm0rt41PC commented 2 months ago

Is your feature request related to a problem or use case?

On a shared server, I have multiple users and in order to debug what was catched by ForceFolder and ForceProcess I need to have some log but even with the reg HKLM\SYSTEM\CurrentControlSet\Services\SbieSvc I'm not able to view what was catched.

Describe the solution you'd like

I would like to have a Windows eventlog indicating that the driver has caught process XXXX due to rule YYYYY.

Describe alternatives you've considered

None