Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <Sysmon schemaversion="1.0">
- <Configuration>
- <!-- Capture MD5 Hashes -->
- <Hashing>SHA1</Hashing>
- <!-- Enable Network Logging -->
- <Network />
- <!-- Enable Image Load Logging -->
- <ImageLoading/>
- </Configuration>
- <Rules>
- <!-- Include all Processes EXCEPT certain processes that cause high event volumes -->
- <!-- This will prevent the logging of processes located in c:\Program Files\Google or
- anything with Symantec in the path -->
- <ProcessCreate default="include">
- <Image condition="begin with">"C:\Program Files\Google"</Image>
- <Image condition="contains">Symantec</Image>
- </ProcessCreate>
- <!-- Do not log network connections of a certain address-->
- <NetworkConnect default="include">
- <DestinationHostname condition="end with">jon.glass</DestinationHostname>
- </NetworkConnect>
- </Rules>
- </Sysmon>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement