One problem with Windows is that it's always been difficult to know what exactly it's doing in the background at any given moment. When you start up an application, what's it doing that we can't see?
Microsoft has released Sysmon 13 with a new security feature that detects if a process has been tampered using process hollowing or process herpaderping techniques. To evade detection by security ...
Microsoft has released Sysmon 15, converting it into a protected process and adding the new ‘FileExecutableDetected’ option to log when executable files are created. For those not familiar with Sysmon ...