Comments (12)
Your browser has a proxy most likely, so the proxy resolved the dns instead
from sysmon-config.
Hello @taherkaraki ,
Thank you for your feedback. Its not this. I don`t have any proxy set. I forgot to mention that all of the machines which I have tested on are newly installed (fresh Windows).
Must be something else but I didn`t yet figure it out what it is.
from sysmon-config.
Run wireshark and see if you have any dns traffic
from sysmon-config.
@taherkaraki - I tested it with wireshark. ran capture, accessed websites, including below apple.com, and it shows the DNS traffic:
but on the sysmon operational event viewer logs - no sign of them
from sysmon-config.
Are you sure your sysmon config does not exclude the browser?
from sysmon-config.
Are you sure your sysmon config does not exclude the browser?
@taherkaraki i'm using the swifton config. I changed nothing in it.
from sysmon-config.
Comment From config:
<!--OPERATIONS: Chrome and Firefox prefetch DNS lookups, or use alternate DNS lookup methods Sysmon won't capture. You need to turn these off.
Search for Group Policy for these browsers to configure this.-->
from sysmon-config.
@taherkaraki - disabled the DNS lookup setting in edge (Use secure DNS to specify how to lookup the network address for websites) and still no sign in Sysmon operational of the DNS records from websites I`m accessing.
from sysmon-config.
later update: it turns out that from firefox I receive every DNS query in Event Viewer. the problem seems to be in edge and chrome. did checked the proxy settings, DNS lookup - nothing which can solve this
from sysmon-config.
Same issue, Is there a solution?
from sysmon-config.
Related Issues (20)
- About powershell cmdlet module
- Parser error with Sysmon v13.32 installation/configuration
- Own Microsoft Sentinel Workbook is planned? Or recommended Microsoft Sentinel Workbook? HOT 2
- Sysmon for Linux HOT 3
- Event Id 10 not being generated HOT 1
- Event 22 not generating HOT 1
- Outdated link inside the sysmon-config HOT 1
- Capturing deleted files
- config causing 35 second delay opening modern MS Office file formats (.docx & .xlsx etc)
- Include vs Exclude precedence HOT 1
- Sysmon 14.13: Crash with sysmon-config on Windows 2012 R2 HOT 1
- 28 Event ID... HOT 1
- Incorrect XML Configuration - Sysmon 14.16
- Sysmon v15.0 & 29 Events HOT 2
- Exclude _PSSCRIPTPOLICYTEST_xxxxx.ps1 in fullfilepath in AppLocker events from forwarding to WEC
- Sysmon Installation Issue - wevtutil.exe returned failure HOT 2
- sysmon erronious sysmon not installed error
- Can help show me the code how to sysmon use eventID 23, 26 ? HOT 1
- Sysmonconfig XML error log when attempting to install.
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from sysmon-config.