microsoft / microsoft/SysinternalsEBPF

sysmonforlinux Event ID 11 - Empty TargetFilename

Open
#54 0 comments 0 reactions 1 assignee View on GitHub

@MarioHewardt is already working on this.

Since Jun 21, 2024.

investigate
Dominant language
C
Stars
288
Forks
38
Avg merge
21d 13h
Merged PRs (30d)
1

Description

Describe the bug
All events ID 11 - File Create are missing values in TargetFilename field. Only dash (-) is being shown.

kernel version
Linux version 4.19.90-2107.6.0.0248.35 and bpf co-re is disabled
SysinternalsEBPF version
Tested on 1.3.0.0
Sysmon version
Tested on 1.3.2
Sysmon configuration
I used the following configuration to record all events ID 11 logs like this



log
Jun 21 17:36:25 localhost sysmon[769]: 11241100x800000000000000090134Linux-Sysmon/Operationallocalhost.localdomain-2024-06-21 09:36:25.959{011548b0-48fc-6675-9d14-4ab268550000}1074/usr/sbin/rsyslogd-2024-06-21 09:36:25.959-

Expected behavior
A path and file name is expected in TargetFilename

problems in the code
I found that there seems to be a problem in the inline function “fdToPath” causing this problem,This function is in the sysinternalsEBPF_helpers.c file.
1718964711442

the offset fd_path descript like this "the path struct is two pointers from the start of the file struct. This will be confirmed in the testing phase", so I think the mechanism address is “task” which is incorrect, “task” needs to be replaced by “file”

Thank you.
Regards,
wiggens

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.