Skip to content

Interesting Behaviors

RagingRedRiot edited this page Aug 7, 2024 · 4 revisions

Notes about undesired behaviors that aren't considered to be bugs or issues.
At the time of reporting, there's no intentions to "fix" these behaviors.

service.version logging

  • [08-07-2024] [Reported by RagingRedRiot] Occasionally the service.version field in the 12345 log will return an error that the OS cannot find the service binary. It is believed this behavior is due to the binary being written to be "non-blocking" by not persistently querying the OS for valid responses.

Sysmon Process Injection Alerts

  • [08-07-2024] [Reported by RagingRedRiot] Sysmon might identify Audit Inspector as performing Process Injection.
Clone this wiki locally