sysmon-modular
sysmon-modular copied to clipboard
Adding interesting_files.xml
Add collection of interesting files in FileDelete event type to use with a management configuration.
I have specifically targetted executables and added example of exclusion. As I noticed a lot of configs were using contains, I have also split out individual TargetFilename filters using 'end with' for better performance.