Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,170 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I am using Sysmon and sending the logs to Wazuh for threat detection. It shows a level 12 event that pertains to sdbinst.exe. The event data command line was C:\WINDOWS\System32\sdbinst.exe -m -bg but according to MS documentation the options used by the .exe are not allowable.
See https://learn.microsoft.com/en-us/windows/deployment/planning/using-the-sdbinstexe-command-line-tool
Does this mean the the exe is malicious?