Skip to content

Commit

Permalink
Merge pull request #54 from j91321/auto-updates
Browse files Browse the repository at this point in the history
[Config] Update sysmon configs
  • Loading branch information
j91321 committed Jan 2, 2023
2 parents 2c62ac1 + 481c3a2 commit 3c2dc50
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion files/olafhartong-sysmonconfig.xml
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@
<OriginalFileName name="technique_id=T1222,technique_name=File Permissions Modification" condition="is">takeown.exe</OriginalFileName>
<OriginalFileName name="technique_id=T,technique_name=" condition="is">makecab.exe</OriginalFileName>
<OriginalFileName name="technique_id=T,technique_name=" condition="is">wusa.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1490,technique_name=Inhibit System Recovery" condition="is">vassadmin.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1490,technique_name=Inhibit System Recovery" condition="is">vssadmin.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1033,technique_name=System Owner/User Discovery" condition="contains any">nltest.exe;nltestk.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1202,technique_name=Indirect Command Execution" condition="is">winrs.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1548.002,technique_name=Bypass User Account Control" condition="is">computerdefaults.exe</OriginalFileName>
Expand Down Expand Up @@ -2320,8 +2320,10 @@
<Image condition="begin with">C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\</Image>
<Image condition="contains">\MicrosoftEdge_X64_</Image>
</Rule>
<Image condition="is">C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\XDelta64\xdelta3.exe</Image>
<Image condition="contains">unknown process</Image>
<Image condition="is">C:\Program Files\Microsoft VS Code\Code.exe</Image>
<Image condition="is">C:\Windows\System32\wbem\WMIADAP.exe</Image>
</ProcessTampering>
</RuleGroup>
<!-- Event ID 26 == File Delete and overwrite events, does NOT save the file - Includes -->
Expand Down

0 comments on commit 3c2dc50

Please sign in to comment.