|
1154 | 1154 | }
|
1155 | 1155 | }
|
1156 | 1156 | },
|
| 1157 | + "Microsoft Sysmon": { |
| 1158 | + "events":{ |
| 1159 | + "Sysmon Service Status Changed ": { |
| 1160 | + "0": { |
| 1161 | + "level": "Information", |
| 1162 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1163 | + "provider": "Microsoft-Windows-Sysmon", |
| 1164 | + "notes": "Sysmon Service Status Changed" |
| 1165 | + } |
| 1166 | + }, |
| 1167 | + "Process creation": { |
| 1168 | + "1": { |
| 1169 | + "level": "Information", |
| 1170 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1171 | + "provider": "Microsoft-Windows-Sysmon", |
| 1172 | + "notes": "Process creation" |
| 1173 | + } |
| 1174 | + }, |
| 1175 | + "Process changed file creation time": { |
| 1176 | + "2": { |
| 1177 | + "level": "Information", |
| 1178 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1179 | + "provider": "Microsoft-Windows-Sysmon", |
| 1180 | + "notes": "A process changed a file creation time" |
| 1181 | + } |
| 1182 | + }, |
| 1183 | + "Network connection": { |
| 1184 | + "3": { |
| 1185 | + "level": "Information", |
| 1186 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1187 | + "provider": "Microsoft-Windows-Sysmon", |
| 1188 | + "notes": "Network connection" |
| 1189 | + } |
| 1190 | + }, |
| 1191 | + "Sysmon service state changed": { |
| 1192 | + "4": { |
| 1193 | + "level": "Information", |
| 1194 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1195 | + "provider": "Microsoft-Windows-Sysmon", |
| 1196 | + "notes": "Sysmon service state changed" |
| 1197 | + } |
| 1198 | + }, |
| 1199 | + "Process terminated": { |
| 1200 | + "5": { |
| 1201 | + "level": "Information", |
| 1202 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1203 | + "provider": "Microsoft-Windows-Sysmon", |
| 1204 | + "notes": "Process terminated" |
| 1205 | + } |
| 1206 | + }, |
| 1207 | + "Driver loaded": { |
| 1208 | + "6": { |
| 1209 | + "level": "Information", |
| 1210 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1211 | + "provider": "Microsoft-Windows-Sysmon", |
| 1212 | + "notes": "Driver loaded" |
| 1213 | + } |
| 1214 | + }, |
| 1215 | + "Image loaded": { |
| 1216 | + "7": { |
| 1217 | + "level": "Information", |
| 1218 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1219 | + "provider": "Microsoft-Windows-Sysmon", |
| 1220 | + "notes": "Image loaded" |
| 1221 | + } |
| 1222 | + }, |
| 1223 | + "Create Remote Thread": { |
| 1224 | + "8": { |
| 1225 | + "level": "Information", |
| 1226 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1227 | + "provider": "Microsoft-Windows-Sysmon", |
| 1228 | + "notes": "CreateRemoteThread" |
| 1229 | + } |
| 1230 | + }, |
| 1231 | + "Raw Access Read": { |
| 1232 | + "9": { |
| 1233 | + "level": "Information", |
| 1234 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1235 | + "provider": "Microsoft-Windows-Sysmon", |
| 1236 | + "notes": "RawAccessRead" |
| 1237 | + } |
| 1238 | + }, |
| 1239 | + "Process Access": { |
| 1240 | + "10": { |
| 1241 | + "level": "Information", |
| 1242 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1243 | + "provider": "Microsoft-Windows-Sysmon", |
| 1244 | + "notes": "ProcessAccess" |
| 1245 | + } |
| 1246 | + }, |
| 1247 | + "File Create": { |
| 1248 | + "11": { |
| 1249 | + "level": "Information", |
| 1250 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1251 | + "provider": "Microsoft-Windows-Sysmon", |
| 1252 | + "notes": "FileCreate" |
| 1253 | + } |
| 1254 | + }, |
| 1255 | + "Registry Create/Delete": { |
| 1256 | + "12": { |
| 1257 | + "level": "Information", |
| 1258 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1259 | + "provider": "Microsoft-Windows-Sysmon", |
| 1260 | + "notes": "RegisteryEvent (Object create and Delete)" |
| 1261 | + } |
| 1262 | + }, |
| 1263 | + "Registry Value Set": { |
| 1264 | + "13": { |
| 1265 | + "level": "Information", |
| 1266 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1267 | + "provider": "Microsoft-Windows-Sysmon", |
| 1268 | + "notes": "RegisteryEvent value set" |
| 1269 | + } |
| 1270 | + }, |
| 1271 | + "Registry Key/Value Rename": { |
| 1272 | + "14": { |
| 1273 | + "level": "Information", |
| 1274 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1275 | + "provider": "Microsoft-Windows-Sysmon", |
| 1276 | + "notes": "RegisteryEvent key and value rename" |
| 1277 | + } |
| 1278 | + }, |
| 1279 | + "File Create Stream Hash": { |
| 1280 | + "15": { |
| 1281 | + "level": "Information", |
| 1282 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1283 | + "provider": "Microsoft-Windows-Sysmon", |
| 1284 | + "notes": "FileCreateStreamHash" |
| 1285 | + } |
| 1286 | + }, |
| 1287 | + "Service Configuration Change": { |
| 1288 | + "16": { |
| 1289 | + "level": "Information", |
| 1290 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1291 | + "provider": "Microsoft-Windows-Sysmon", |
| 1292 | + "notes": "ServiceConfigurationChange" |
| 1293 | + } |
| 1294 | + }, |
| 1295 | + "Pipe Created": { |
| 1296 | + "17": { |
| 1297 | + "level": "Information", |
| 1298 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1299 | + "provider": "Microsoft-Windows-Sysmon", |
| 1300 | + "notes": "PipeEvent pipe created" |
| 1301 | + } |
| 1302 | + }, |
| 1303 | + "Pipe Connected": { |
| 1304 | + "18": { |
| 1305 | + "level": "Information", |
| 1306 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1307 | + "provider": "Microsoft-Windows-Sysmon", |
| 1308 | + "notes": "PipeEvent pipe connected" |
| 1309 | + } |
| 1310 | + }, |
| 1311 | + "WMI Filter Activity": { |
| 1312 | + "19": { |
| 1313 | + "level": "Information", |
| 1314 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1315 | + "provider": "Microsoft-Windows-Sysmon", |
| 1316 | + "notes": "WMIEvent WMIEvenFilter activity detected" |
| 1317 | + } |
| 1318 | + }, |
| 1319 | + "WMI Consumer Activity": { |
| 1320 | + "20": { |
| 1321 | + "level": "Information", |
| 1322 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1323 | + "provider": "Microsoft-Windows-Sysmon", |
| 1324 | + "notes": "WMIEvent Consumer activity detected" |
| 1325 | + } |
| 1326 | + }, |
| 1327 | + "WMI Consumer to Filter Activity": { |
| 1328 | + "21": { |
| 1329 | + "level": "Information", |
| 1330 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1331 | + "provider": "Microsoft-Windows-Sysmon", |
| 1332 | + "notes": "WMIEvent Consumer to filter activity detected" |
| 1333 | + } |
| 1334 | + }, |
| 1335 | + "DNS Query": { |
| 1336 | + "22": { |
| 1337 | + "level": "Information", |
| 1338 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1339 | + "provider": "Microsoft-Windows-Sysmon", |
| 1340 | + "notes": "DNSEvent DNS Query" |
| 1341 | + } |
| 1342 | + }, |
| 1343 | + "File Delete": { |
| 1344 | + "23": { |
| 1345 | + "level": "Information", |
| 1346 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1347 | + "provider": "Microsoft-Windows-Sysmon", |
| 1348 | + "notes": "FileDelete a file delete was detected" |
| 1349 | + } |
| 1350 | + }, |
| 1351 | + "Clipboard Change": { |
| 1352 | + "24": { |
| 1353 | + "level": "Information", |
| 1354 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1355 | + "provider": "Microsoft-Windows-Sysmon", |
| 1356 | + "notes": "ClipboardChange new content in clipboard" |
| 1357 | + } |
| 1358 | + }, |
| 1359 | + "Process Tampering": { |
| 1360 | + "25": { |
| 1361 | + "level": "Information", |
| 1362 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1363 | + "provider": "Microsoft-Windows-Sysmon", |
| 1364 | + "notes": "ProcessTampering process image change" |
| 1365 | + } |
| 1366 | + }, |
| 1367 | + "File Delete Detected": { |
| 1368 | + "26": { |
| 1369 | + "level": "Information", |
| 1370 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1371 | + "provider": "Microsoft-Windows-Sysmon", |
| 1372 | + "notes": "File Delete Detected" |
| 1373 | + } |
| 1374 | + }, |
| 1375 | + "Error": { |
| 1376 | + "255": { |
| 1377 | + "level": "Information", |
| 1378 | + "channel": "Microsoft-Windows-Sysmon/Operational", |
| 1379 | + "provider": "Microsoft-Windows-Sysmon", |
| 1380 | + "notes": "Sysmon error" |
| 1381 | + } |
| 1382 | + } |
| 1383 | + } |
| 1384 | + }, |
1157 | 1385 | "Windows Defender": {
|
1158 | 1386 | "events": {
|
1159 | 1387 | "ACG Audit": {
|
|
0 commit comments