Giter Site home page Giter Site logo

Comments (12)

taherkaraki avatar taherkaraki commented on September 13, 2024

Your browser has a proxy most likely, so the proxy resolved the dns instead

from sysmon-config.

patzak88 avatar patzak88 commented on September 13, 2024

Hello @taherkaraki ,

Thank you for your feedback. Its not this. I don`t have any proxy set. I forgot to mention that all of the machines which I have tested on are newly installed (fresh Windows).

Must be something else but I didn`t yet figure it out what it is.

from sysmon-config.

taherkaraki avatar taherkaraki commented on September 13, 2024

Run wireshark and see if you have any dns traffic

from sysmon-config.

patzak88 avatar patzak88 commented on September 13, 2024

@taherkaraki - I tested it with wireshark. ran capture, accessed websites, including below apple.com, and it shows the DNS traffic:

image

but on the sysmon operational event viewer logs - no sign of them

from sysmon-config.

taherkaraki avatar taherkaraki commented on September 13, 2024

Are you sure your sysmon config does not exclude the browser?

from sysmon-config.

patzak88 avatar patzak88 commented on September 13, 2024

Are you sure your sysmon config does not exclude the browser?

@taherkaraki i'm using the swifton config. I changed nothing in it.

from sysmon-config.

taherkaraki avatar taherkaraki commented on September 13, 2024

Comment From config:

	<!--OPERATIONS:	Chrome and Firefox prefetch DNS lookups, or use alternate DNS lookup methods Sysmon won't capture. You need to turn these off.
					Search for Group Policy for these browsers to configure this.-->

from sysmon-config.

patzak88 avatar patzak88 commented on September 13, 2024

@taherkaraki - disabled the DNS lookup setting in edge (Use secure DNS to specify how to lookup the network address for websites) and still no sign in Sysmon operational of the DNS records from websites I`m accessing.

from sysmon-config.

patzak88 avatar patzak88 commented on September 13, 2024

later update: it turns out that from firefox I receive every DNS query in Event Viewer. the problem seems to be in edge and chrome. did checked the proxy settings, DNS lookup - nothing which can solve this

from sysmon-config.

pulpon6 avatar pulpon6 commented on September 13, 2024

Same issue, Is there a solution?

from sysmon-config.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.