sysmon-config icon indicating copy to clipboard operation
sysmon-config copied to clipboard

File updated - Sysmon Event ID

Open kont45 opened this issue 4 years ago • 1 comments

For custom rules as file overwrite / create which Event ID should we use to logs changes? Event ID 11 or 2? For example I need log file when changed in path c:\programdata\file.log

kont45 avatar Jul 17 '20 08:07 kont45

It sounds like you want to monitor when someone replaces or modifies a specific file. Sysmon is not the best tool for auditing detailed changes to the file system. For this, you should look into Windows File System auditing.

jokezone avatar Jul 17 '20 08:07 jokezone