Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Does not equal filtering question

$
0
0

I want to see all the executables run in the user's home directory. I can see that information with the ProcessStart.ExtraneousInfo *C:\Users* but when I try to filter out all of the usual executables that run in that folder it does not seem to filter them.

 

Example of the rule I created:

procstart.JPG

 

Any suggestions on how to get this working?


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>