|
|
2 gadi atpakaļ | |
|---|---|---|
| .. | ||
| README.md | 2 gadi atpakaļ | |
| beacon.h | 2 gadi atpakaļ | |
| bofcompile.bat | 2 gadi atpakaļ | |
| silencesysmon.c | 2 gadi atpakaļ | |
| silencesysmon.cna | 2 gadi atpakaļ | |
| silencesysmon.h | 2 gadi atpakaļ | |
| silencesysmon.o | 2 gadi atpakaļ | |
Silence the Sysmon service by patching its capability to write ETW events to the log.
Restarting the Sysmon service or the system itself will clear the patch and Sysmon will resume working normally. Altough this will not leave any traces in the log, there will be a time gap between the last and first new event.
<pid>: the process ID of the Sysmon service running on the system.silencesysmon <sysmon pid>x64 Native Tools Command Prompt for VS <2019/2022> terminal.bofcompile.bat script to compile the object file.