cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1725
Views
49
Helpful
15
Replies

CSA Tuning process

taylr
Level 1
Level 1

Can anyone point me to a resource to research the Alerts that come up in the Event log so that I know if it should be allowed or denied? For instance. How would I know if this process not supposed to be able to insert code into another process?

TESTMODE: The process 'C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\cda0537e8e2624c74cdaea2d34c7c7df\update\update.exe' (as user NT AUTHORITY\SYSTEM) attempted to insert code ('Windows Message code 1030') into another process. The process 'unknown process' was targeted. The operation would have been denied. Details Rule 1009 Wizard

15 Replies 15

taylr
Level 1
Level 1

Thanks for all of your comments.

Review Cisco Networking for a $25 gift card