cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
848
Views
0
Helpful
2
Replies

Windows System32 Directory File Creation

sameer.devlekar
Level 1
Level 1

Hi Folks,

I get sevral alerts from my IDS system says, "Windows System32 Directory File Creation" as an event.

Could you please help me out understand the exact meaning for this alerts.

Thanks in advance,

Sameer

2 Replies 2

johan.kellerman
Level 1
Level 1

Hi

This is pretty straith forward. A file has been created in the ..%windowsroot%\system32 directory.

If you turn on verbose logging for this signature you can see what file has been created.

Br

Johan Kellerman

Hi Johan,

I tried using that but, the report doesn't seem to shows any useful info. Please let me know if we have any other possible way to investigate this cause.

Thanks,

Sameer

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card