SysmonCommunityGuide
SysmonCommunityGuide copied to clipboard
Example usage of is-any feature new to sysmon v11.0
In Sysinternals Video Update for June 2020 on Youtube, minute 4:45 describes a new feature of sysmon v11 providing new "is-all" filtering condition as ability to specify multiple conditions and require all of them to be satisfied before an event is logged.
Sysmon (v12) schema shows these filters which are new to me:
The video does not provide an example of usage of these (these) new filtering options. I think it would be helpful to document usage here so folks (like me) can get up and running with it faster.
Description is empty, can you provide one