Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new Event IDs for virus/tamper matches #718

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Commits on Jul 2, 2020

  1. Add new Event IDs for virus/tamper matches

    xample logs...
    
    2020 Jul 01 14:29:17 WinEvtLog: Application: ERROR(51): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123:       Security Risk Found! signature123 in File: c:\windows\system32\windowspowershell\v1.0\powershell.exe by: scan scan.  Action: .  Action Description: Access Denied
    
    2020 Jul 01 14:08:20 WinEvtLog: Application: INFORMATION(45): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123:       Scan type: Tamper Protection Scan  Event: Tamper Protection Detection  Security risk detected: C:\PROGRAM FILES (X86)\THING\THING.EXE  File: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin\ccSvcHst.exe  Location: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin  Computer: AGENT123  User: SYSTEM  Action taken: Access denied  Date found: 01 July 2020  14:08:20
    jjrbg committed Jul 2, 2020
    Configuration menu
    Copy the full SHA
    4cf2f6c View commit details
    Browse the repository at this point in the history