Thank you Carlos, for you support, but unfortunately the rule you provided doesn't seem to work. I still receive email alerts...
Wazuh Notification.
2026 Feb 05 12:01:46
Received From: (NEW-PC) any->EventChannel
Rule: 92058 fired (level 12) -> "Application Compatibility Database launched"
User: NT AUTHORITY\SYSTEM
Portion of the log(s):
{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2026-02-05T10:01:54.1214586Z","eventRecordID":"475400","processID":"4860","threadID":"7084","channel":"Microsoft-Windows-Sysmon/Operational","computer":"NEW-PC.ga.intranet","severityValue":"INFORMATION","message":"\"Process Create:\r\nRuleName: -\r\nUtcTime: 2026-02-05 10:01:54.117\r\nProcessGuid: {f0f0f557-6a92-6984-aa1e-000000001400}\r\nProcessId: 3280\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.26100.7705 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: MicrosoftÂŽ WindowsÂŽ Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\WINDOWS\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\WINDOWS\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM
\r\nLogonGuid: {f0f0f557-ab30-6981-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA256=7B44604F1C8C89E1AB00AB4953A379B03788B73C66342754CB564A8C4E6E4906\r\nParentProcessGuid: {00000000-0000-0000-0000-000000000000}\r\nParentProcessId: 8876\r\nParentImage: -\r\nParentCommandLine: -\r\nParentUser: -\""},"eventdata":{"utcTime":"2026-02-05 10:01:54.117","processGuid":"{f0f0f557-6a92-6984-aa1e-000000001400}","processId":"3280","image":"C:\\\\Windows\\\\System32\\\\sdbinst.exe","fileVersion":"10.0.26100.7705 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"MicrosoftÂŽ WindowsÂŽ Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\WINDOWS\\\\System32\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\WINDOWS\\\\system32\\\\","user":"NT AUTHORITY\\\\SYSTEM","logonGuid":"{f0f0f557-ab30-6981-e703-000000000000}","logonId":"0x3e7","terminalSessionI
d":"0","integrityLevel":"System","hashes":"SHA256=7B44604F1C8C89E1AB00AB4953A379B03788B73C66342754CB564A8C4E6E4906","parentProcessGuid":"{00000000-0000-0000-0000-000000000000}","parentProcessId":"8876"}}}
win.system.providerName: Microsoft-Windows-Sysmon
win.system.providerGuid: {5770385f-c22a-43e0-bf4c-06f5698ffbd9}
win.system.eventID: 1
win.system.version: 5
win.system.level: 4
win.system.task: 1
win.system.opcode: 0
win.system.keywords: 0x8000000000000000
win.system.systemTime: 2026-02-05T10:01:54.1214586Z
win.system.eventRecordID: 475400
win.system.processID: 4860
win.system.threadID: 7084
win.system.channel: Microsoft-Windows-Sysmon/Operational
win.system.computer: NEW-PC.ga.intranet
win.system.severityValue: INFORMATION
win.system.message: "Process Create:
RuleName: -
UtcTime: 2026-02-05 10:01:54.117
ProcessGuid: {f0f0f557-6a92-6984-aa1e-000000001400}
ProcessId: 3280
Image: C:\Windows\System32\sdbinst.exe
FileVersion: 10.0.26100.7705 (WinBuild.160101.0800)
Description: Application Compatibility Database Installer
Product: MicrosoftÂŽ WindowsÂŽ Operating System
Company: Microsoft Corporation
OriginalFileName: sdbinst.exe
CommandLine: C:\WINDOWS\System32\sdbinst.exe -m -bg
CurrentDirectory: C:\WINDOWS\system32\
LogonGuid: {f0f0f557-ab30-6981-e703-000000000000}
LogonId: 0x3E7
TerminalSessionId: 0
IntegrityLevel: System
Hashes: SHA256=7B44604F1C8C89E1AB00AB4953A379B03788B73C66342754CB564A8C4E6E4906
ParentProcessGuid: {00000000-0000-0000-0000-000000000000}
ParentProcessId: 8876
ParentImage: -
ParentCommandLine: -
ParentUser: -"
win.eventdata.utcTime: 2026-02-05 10:01:54.117
win.eventdata.processGuid: {f0f0f557-6a92-6984-aa1e-000000001400}
win.eventdata.processId: 3280
win.eventdata.image: C:\\Windows\\System32\\sdbinst.exe
win.eventdata.fileVersion: 10.0.26100.7705 (WinBuild.160101.0800)
win.eventdata.description: Application Compatibility Database Installer
win.eventdata.product: MicrosoftÂŽ WindowsÂŽ Operating System
win.eventdata.company: Microsoft Corporation
win.eventdata.originalFileName: sdbinst.exe
win.eventdata.commandLine: C:\\WINDOWS\\System32\\sdbinst.exe -m -bg
win.eventdata.currentDirectory: C:\\WINDOWS\\system32\\
win.eventdata.user: NT AUTHORITY\\SYSTEM
win.eventdata.logonGuid: {f0f0f557-ab30-6981-e703-000000000000}
win.eventdata.logonId: 0x3e7
win.eventdata.terminalSessionId: 0
win.eventdata.integrityLevel: System
win.eventdata.hashes: SHA256=7B44604F1C8C89E1AB00AB4953A379B03788B73C66342754CB564A8C4E6E4906
win.eventdata.parentProcessGuid: {00000000-0000-0000-0000-000000000000}
win.eventdata.parentProcessId: 8876
--END OF NOTIFICATION