-
Notifications
You must be signed in to change notification settings - Fork 111
Description
A few days ago, I found that this SysmonSimulator doesn't work anymore because the System Monitor doesn't log the simulator's artificial behavior that was supposed to generate a specific ID of the log.
For example, I wanted to create an EID 8 log, so I hit the command
"C:\Users\3NR1QUE\Desktop\DivePortal\Sysmon\SysmonSimulator.exe" -eid 8And I received the log that occurred by that command
Process Create:
RuleName: -
UtcTime: 2024-02-27 08:43:23.928
ProcessGuid: {0b7407af-a0ab-65dd-0b23-00000000c301}
ProcessId: 35296
Image: C:\Users\3NR1QUE\Desktop\DivePortal\Sysmon\SysmonSimulator.exe
FileVersion: -
Description: -
Product: -
Company: -
OriginalFileName: -
CommandLine: "C:\Users\3NR1QUE\Desktop\DivePortal\Sysmon\SysmonSimulator.exe" -eid 8
CurrentDirectory: C:\Users\3NR1QUE\Desktop\DivePortal\Sysmon\
User: KLOJURE\LUEX
LogonGuid: {0b7407af-71bb-65dd-9385-060000000000}
LogonId: 0x68593
TerminalSessionId: 1
IntegrityLevel: Medium
Hashes: SHA256=BF7A223831887EF706140007CCF00D6C6069DEDE7335E84040EC114C09DEC343
ParentProcessGuid: {0b7407af-8a87-65dd-f21f-00000000c301}
ParentProcessId: 46488
ParentImage: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ParentCommandLine: C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe
ParentUser: KLOJURE\LUEX
It means Sysmon logged SysmonSimulator.exe's EID 8 event generation process as a process creation of SysmonSimulator.exe -eid 8, instead of the real event whose EID is 8(and that was what SysmonSimulator has expected.).
The other tries with different EID values resulted in the same log(Process creation/termination of SysmonSimulator.exe.). It seems that the internal logic of Sysmon has changed.
I found that this repository hasn't been maintained for around 2 years now. I wonder if this unavailability issue will be taken care of in the future(Or, just make my version of SysmonSimulator instead?).