You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A few days ago, I found that this SysmonSimulator doesn't work anymore because the System Monitor doesn't log the simulator's artificial behavior that was supposed to generate a specific ID of the log.
For example, I wanted to create an EID 8 log, so I hit the command
It means Sysmon logged SysmonSimulator.exe's EID 8 event generation process as a process creation of SysmonSimulator.exe -eid 8, instead of the real event whose EID is 8(and that was what SysmonSimulator has expected.).
The other tries with different EID values resulted in the same log(Process creation/termination of SysmonSimulator.exe.). It seems that the internal logic of Sysmon has changed.
I found that this repository hasn't been maintained for around 2 years now. I wonder if this unavailability issue will be taken care of in the future(Or, just make my version of SysmonSimulator instead?).
The text was updated successfully, but these errors were encountered:
A few days ago, I found that this SysmonSimulator doesn't work anymore because the System Monitor doesn't log the simulator's artificial behavior that was supposed to generate a specific ID of the log.
For example, I wanted to create an EID 8 log, so I hit the command
And I received the log that occurred by that command
It means Sysmon logged
SysmonSimulator.exe
's EID 8 event generation process as a process creation ofSysmonSimulator.exe -eid 8
, instead of the real event whose EID is8
(and that was whatSysmonSimulator
has expected.).The other tries with different EID values resulted in the same log(Process creation/termination of
SysmonSimulator.exe
.). It seems that the internal logic of Sysmon has changed.I found that this repository hasn't been maintained for around 2 years now. I wonder if this unavailability issue will be taken care of in the future(Or, just make my version of
SysmonSimulator
instead?).The text was updated successfully, but these errors were encountered: