Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: InfoSec Handlers Diary Blog InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Sysinternals: Procmon and Sysmon update

Published: 2021-04-25
Last Updated: 2021-04-25 11:34:41 UTC
by Didier Stevens (Version: 1)
1 comment(s)

New versions of Procmon and Sysmon were released.

Sysmon supports a new rule: FileDeletedDetected. Use it to log deletions (without archiving the deleted file).

Didier Stevens
Senior handler
Microsoft MVP
blog.DidierStevens.com DidierStevensLabs.com

Keywords: procmon sysmon
1 comment(s)
Diary Archives