-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sysmon v7 requires schema version update. #45
Comments
cxxr
added a commit
to cxxr/sysmon-config
that referenced
this issue
Jan 9, 2018
Should close SwiftOnSecurity#45, and it works on my machine. I couldn't find any good docs on what's actually different, though.
cxxr
added a commit
to cxxr/sysmon-config
that referenced
this issue
Jan 9, 2018
Should close SwiftOnSecurity#45, and it works on my machine. I couldn't find any good docs on what's actually different, though.
Be aware that the rules for combining rule conditions have changed in 7.01: From Sysmon 6.1:
From Sysmon 7.01:
Regards |
cxxr
added a commit
to DefenseStorm/sysmon-config
that referenced
this issue
Jan 23, 2018
Should close SwiftOnSecurity#45, and it works on my machine. I couldn't find any good docs on what's actually different, though.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Looks like sysmon v7 doesn't accept setting the config with a v3.30 schema. Updating the schema version to 4.0 seems to fix this.
I havn't found any documentation on what's changed between 3.30 and 4.0, but the 3.30 file with an updated schema version seems to still work?
The text was updated successfully, but these errors were encountered: