We are observing data stream modification/creation in the AD server in satging folder.
We are observing data stream modification/creation in the file path D:\Windows\SYSVOL\staging\domain\ContentSet{F0D884-0B78-4D32-898D-F4FAB7C0B63C}-{FC74168C6C-4C79-9379-3A40B4A3FAC0}\35\ by the process “C:\Windows\System32\dfsrs.exe”on the server AD-DC3(also on other AD server) as per McAfee FIM.
Below file some modification for reference:
D:\Windows\SYSVOL\staging\domain\ContentSet{F0DDB884-0B7-898D-F4FAB7C0B63C}-{FC741688-DC6C-4C79-9379-3A40B4A3FAC0}\35\616339-{B542BA0A-DDAE-4232-3-C329ABEC9EC6}-v435-{B542BA0A-DDAE-4232-BAD3-C329ABEC9EC6}-v616339-Downloading.frx
D:\Windows\SYSVOL\staging\domain\ContentSet{F0DDB884-0B78-4D32-898D-F4FABB63C}-{FC741688-DC6C-4C79-9379-3A40B4A3FAC0}\35\616358-{B542BA0A-DDAE-4232-BAD3-C9ABEC9EC6}-v435-{B542BA0A-DDAE-4232-BAD3-C329ABEC9EC6}-v616358-Downloading.frx
D:\Windows\SYSVOL\staging\domain\ContentSet{F0DDB884-0B78-4D32-8-F4F7C0B63C}-{FC741688-DC6C-4C79-9379-3A40B4A3FAC0}\35\616367-{B542BA0A-DDAE-4232-BAD3-C32BEC9EC6}-v435-{B542BA0A-DDA232-BAD3-C329ABEC9EC6}-v616367-Downloading.frx
This modification/creation is normal behavior of DFSR or not?