Update-Sysmon icon indicating copy to clipboard operation
Update-Sysmon copied to clipboard

Add support for Sysmon v11 copy-on-delete

Open jokezone opened this issue 4 years ago • 0 comments

The latest version of Sysmon added the ability to copy deleted/shredded files to a system root ArchiveDirectory. This archive directory is protected with a SYSTEM ACL which prevents users from accessing the contents. Since Update-Sysmon is intended to run as the SYSTEM account, it could be used to synchronize files in this directory with a central file share for analysis by threat hunters.

jokezone avatar Apr 30 '20 18:04 jokezone