Sysmon Configuration Entries - DriverName has no effect
I am running Sysmon v15.14 and have the following config entries: <Sysmon schemaversion="4.90"> <DnsLookup></DnsLookup> <DriverName>AudiusSv</DriverName> <EventFiltering> <RuleGroup…
Is it known that AutoLogon.exe does not remove the DefaultPassword from the LSA Secrets store / Registry?
I was playing with AutoLogon.exe for the first time today and was testing the security around the DefaultPassword. I have found tools that can easily decrypt the password, but that weak security is known. What I wonder though, is if it is known that…
EOL,EOS,EEOS Dates for Sysinternals products
Hii All I wanted to know the End of life (EOL), End of Support (EOS), Extended End of Support (EEOS) dates for the below mentioned sysinternals products. Handle 4Bg Info 4Handle 5Sysinternals Process Monitor 3PsExec 2Process Explorer 17PsGetSid 1PsPing…
Sysmon V15.14: Servers going to "hung state" randomly
Hello, We deployed sysmon V15.14 and facing issues like random servers going into "hung state". I see a ton of "<unknown process> " in the process_path field of Event ID #3 ( Network connection) in sysmon log. Just curious if…
procmon leaves something in place that anti hack software detects
I have licensed software that checks for hacking sw somehow. It got upset when it saw that procmon was running ('monitoring sw running'...) and shut down. When I shutdown procmon and restarted the app it still complained, I had to reboot. Seems like…
RDCMan v2.90 Doesn't honor 'Desktop background'
I am using RDCMan v2.90 and find that when connecting to Windows Server 2012, 2012R2, 2016 or 2019 the desktop background is shown even when RDCMan Experience settings have the Desktop background option disabled. I have also tried setting connection…
Adjust Wallpaper Diferent Resolutions
In my company some users has a monitor to use as a second screen of your notebook. The screen resolutions of this monitors are different than the notebook resolution and the wallpaper that was set by BGInfo appears deformed. There is a way to setup…
RDCman must support webauthn to stay relevant!
RDCMan from sysinternals does not support webauthn and can't use FIDO2 keys or Passkeys which are in preview for Entra ID now. Without this feature RDCman is basically useless going forward. Can someone at Microsoft/Sysinternals PLEASE look into this? Or…
bginfo 4.28 - bug in saving and/or loading complex user defined fields detected
Hi all, I think I detected a bug in bginfo when saving and loading a more complex user defined wmi query. My situation: I am saving my settings in a bgi file, not in the registry I wanted to shorten the network output of bginfo, so I tried to…
I am unable to find msi for RDCMAN V2.90
I am unable to find set up file for remote connection desktop manager V 2.90. The one available on the below link is not the correct one. https://download.sysinternals.com/files/RDCMan.zip Please assist me in finding the correct one.
EOL,EOS,EEOS Dates for sysinternals
Hi All I Want to know the EOL, EOS, EEOS dates for the Sysinternals products. e.g. handle4, Bg info4, handle5, process monitors, process explorer, psexec2,
System.BadImageFormatException
Hello, I wanted to ask about an error that happened to me lately and that is that when I start the computer I get this message
Output of GFlags "Show Loader Snaps" not visible in DebugView
"Show Loader Snaps" is a very useful GFlag to investigate dependency issue of an application. When using it, I will get the debug output of this flag in the Debug Output windows of Visual Studio 2022 - that is nice. But when using the famous…
RDCMan: Feature request: config option to control whether closing an undocked session disconnects
Folks: It would be very nice to have the following two features, either globally or (more flexibly) per-connection: an option to say "all connections open in a detached window". an option to say "when closing a detached connection…
BgInfo support for PowerShell commands and scripts
Please add PowerShell command and script support to BgInfo. BgInfo currently supports many legacy methods for data collection such as environment variables, registry value, WMI query and VB scripts. Modern system administrators and IT professionals…
BGinfo silent mode not working
Dear Support, I have downloaded the latest version of BGinfo and applied the custom settings. The preview mode is working fine; I can see the hostname and IP address in the right-bottom corner. However, when I run the batch file…
Am I invoking PsExec wrong or is it not working properly?
I am attempting to use PsExec from an admin powershell to spawn a GUI Win32 program from my current session into another session (#1). Like this: ./psexec64 -i 1 path-to-my-exe-to-run Since it didn't work with my program, and returned a negative return…
How do I force Microsoft Teams (PWA) 2.0 on Linux?
I got it working for only couple of my computers/web browsers, but I can't seem to force it. I created a policy that sets "Show Teams preview features" as "on for everyone" "Use new Teams client" as "New Teams by…
sysinternals zoomit recording suddently started giving an error
I'm using zoomit from sysinternals, and one of the most used features I used was the screen recording. I don't know what happened, but it suddently stopped working giving the following error: ZoomIt Error starting recording: Invalid pointer OK …
Unable to connect the VM through RDP manager in SAW machine
Till last monday, I am able to connect the VM which is in SAW through RDP Manager. But now it was not. Post updates, I see this issue. Restarted multiple times and verified but no luck .Need help on this