05/24/2023, 7:04 AM
Can anyone help on docs / suggestions on how to setup FIM for windows. I Was able to follow things related to thanks to @fritz but unsuccessful in implementing them and events are not consistent as expected! I am using osquery 5.5.1 and used following flags,
with the query
SELECT * FROM ntfs_journal_events;
Is there a way to implement FIM for windows to capture FIM process information. like the process that made the file modification!