79200891

Date: 2024-11-18 17:45:39
Score: 1
Natty:
Report link

I did get this figured. In the Windows Advanced Audit Policy, aside from auditing Removable Storage, I also needed to audit "File System" which is not ideal, but I do now get the actual folder created. For others attempting to audit removable storage, you also need to following registry setting set to 1.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Storage\HotplugSecureOpen

This setting also seems to require a reboot.

Reasons:
  • Has code block (-0.5):
  • Self-answer (0.5):
  • Low reputation (1):
Posted by: TonyD