Skip to content

Sysmon issues, PrivacyAgent.exe, massive log flood and cpu usage #106

@Dejmir

Description

@Dejmir

Information:
MajorPrivacy Version: MajorPrivacy-v0.99.10(portable) (same issue on 0.97.0.0)
OS: Windows 10 22H2
Sysmon version: 15.15.0.0
Sysmon config: https://github.com/SwiftOnSecurity/sysmon-config

Description:
When PrivacyAgent.exe is turned on it generates a massive amount of sysmon logs. It generated around 5 000 000 logs in 4minute scope. It's causing high cpu usage generating dns query(log id 22).

None of MajorPrivacy options seems to change anything.

Steps to reproduce:

  1. Install Microsoft Sysmon (v15.15) using the SwiftOnSecurity configuration.
  2. Install and run MajorPrivacy (v0.99.10)(portable).
  3. When MajorPrivacy is asking about the agent start it
  4. After a few seconds PrivacyAgent.exe will start and generate a massive amount of logs causing high cpu usage
  5. We can observe the logs in: Applications and Services Logs > Microsoft > Windows > Sysmon > Operational

Screenshot attachments:

Image Image Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions