Mario Hewardt

Results 123 comments of Mario Hewardt

Hi - Sysmon for Linux is currently only available on amd64. We haven't tested/fixed for other architectures yet.

There was an issue with the rule names which I just fixed. If you want to give it a try and let me know that would be great. For now...

Closing since you were able to verify it now works.

I've pushed a fix that should resolve the issue on RHEL8. You will have to run getOffsets (https://github.com/Sysinternals/SysinternalsEBPF/tree/main/getOffsets) to get this to work.

Hi - Agreed, it does create some confusion. I've removed the EULA

Closing for now. Please reopen if the issue persists with the latest changes.

I've removed the dependency on Mono and updated all the build instructions.

Sorry for the delay here. I'll spend some time next couple of days testing this out and let you know.

@adriankaylor - With the latest changes to Sysmon, I'm not able to reproduce this anymore. Could you try and let me know if it reproduces for you?

This should now be fixed.