• faebudo@infosec.pub
    link
    fedilink
    English
    arrow-up
    2
    ·
    28 days ago

    So they’re going to deliver sysmon.exe as a windows optional feature. There’s nothing native to it. No config management via GPO or CSP or similar. Nothing. Just replacing the scheduled task/powershell script downloading exe and config by one enabling the feature and downloading the config.