Windows System32 Directory File Creation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-22-2010 10:27 PM - edited 03-10-2019 04:58 AM
Hi Folks,
I get sevral alerts from my IDS system says, "Windows System32 Directory File Creation" as an event.
Could you please help me out understand the exact meaning for this alerts.
Thanks in advance,
Sameer
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-23-2010 12:40 AM
Hi
This is pretty straith forward. A file has been created in the ..%windowsroot%\system32 directory.
If you turn on verbose logging for this signature you can see what file has been created.
Br
Johan Kellerman
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-25-2010 11:42 PM
Hi Johan,
I tried using that but, the report doesn't seem to shows any useful info. Please let me know if we have any other possible way to investigate this cause.
Thanks,
Sameer
