What are the different statuses on the trace log in monitor mode? #3042
Replies: 2 comments 7 replies
-
O measns full access, nothing means read access only, X means blocked, although there may be a fake access granted that looks th the boxed process like having one without actually having one |
Beta Was this translation helpful? Give feedback.
-
So are you saying that even though I have a rule giving box access only to the file path "C:\Program Files (x86)*", the boxed process is still getting read only access to my host files for Program Files' child directories? Or are you saying that an empty status in the monitor log has no way to differentiate between the boxed process having read access to the host files and it having read access to the boxed files only? |
Beta Was this translation helpful? Give feedback.
-
I'm running a privacy enhanced box but I also want access to ProgramFiles and all its child directories blocked so I made a file access rule specifically only giving box-access to "C:\Program Files (x86)*". While running the trace log for file access in monitor mode, I noticed that the access to \Device\HarddiskVolume3\Program Files (x86) had an X status but there were multiple entries in the log to child directories within ProgramFiles that had no status at all; the field was empty.
I assume having a status of X means that access was denied and O means that it was allowed. What does having no status mean? Is the program still getting access to child directories within ProgramFiles even though access to the main directory was denied?
Beta Was this translation helpful? Give feedback.
All reactions