Several Events not longer working in Sysmon 14.0?

Niklas Sjögren 41 Reputation points
2022-08-17T09:39:26.84+00:00

Started testing with the new Sysmon version (14.0)...
got the Evt 27 to work...
But,
It seems that some other evts stopped working...!?

Evt 26 (FileDeleteDetect) does not work anymore for me... nothing logs..

I also se less different Events compared to version 13.34

Any one else seeing this?

Using the correct schema versions during tests (4.82 for version 14.0, and 4.81 for version 13.34)

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,087 questions
0 comments No comments
{count} vote

Accepted answer
  1. Michael_N 961 Reputation points
    2022-11-17T19:46:52.403+00:00

    @Niklas Sjögren ,
    I too have done some testing on v14.12 and I actually think Sysmon is working correctly/as intended.

    If you delete a file from the GUI (explorer.exe) the file isn't actually deleted right away. It's just moved to the Recycle Bin. So no delete occurs until you empty the recycle bin.
    But if you delete the file via PowerShell.exe or cmd.exe the recycle bin is bypassed/not used. That's why you see the event from powershell.exe but not explorer.exe.

    Try deleting the file from the GUI/Explorer with SHIFT + DEL (to bypass the recycle bin) and I think you will find that it works (the event is logged).

    A bit unexpected maybe, but technically correct from an API-standpoint which Sysmon has.


7 additional answers

Sort by: Most helpful
  1. Niklas Sjögren 41 Reputation points
    2022-10-31T15:39:07.253+00:00

    Did some testing version 14.11 and Evt. 26 partially works !?

    If I remove a file with powershell it will detect it..
    But if i use explorer.exe it will not... :-/
    Some other event 26 that did not meet my configuration was detected during testing !?
    Tested schema version 4.70, 4,81 and 4.83 with same results...

    Tested my configuration again with version 13.34 and it works as it should...

    Is this someting you can verify in your testsystems?

    0 comments No comments

  2. csinagra 21 Reputation points
    2022-11-04T18:00:46.217+00:00

    Rolled back to version 14.0 as I've been experiencing the same issue with version 14.11 and 14.1 where seeing less events being logged.

    0 comments No comments

  3. Niklas Sjögren 41 Reputation points
    2022-11-14T07:30:58.753+00:00

    Tested version 14.12 this morning and still se strange problem with Evt. 26

    it seems that sysmon is not reading the configuration correct, or partially...!?
    i see Evt 26 beeing logged for events that is not currently in my configuration..?!

    If I test whats in my configuration, I only see logg for things deleted with Powershell, not if I delete with Explorer.

    For the moment testing variants of Hartongs configs.
    https://github.com/olafhartong/sysmon-modular/blob/master/26_file_delete_deteted/include_user_writable_folders.xml

    0 comments No comments