mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Merge pull request #865 from j91321/defender-rules
Windows Defender logsource and rules
This commit is contained in:
commit
2e3669a5a4
26
rules/windows/other/win_defender_disabled.yml
Normal file
26
rules/windows/other/win_defender_disabled.yml
Normal file
@ -0,0 +1,26 @@
|
||||
title: Windows Defender Threat Detection Disabled
|
||||
id: fe34868f-6e0e-4882-81f6-c43aa8f15b62
|
||||
description: Detects disabling Windows Defender threat protection
|
||||
date: 2020/07/28
|
||||
author: Ján Trenčanský
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus
|
||||
status: stable
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1089
|
||||
- attack.t1562.001
|
||||
logsource:
|
||||
product: windows
|
||||
service: windefend
|
||||
detection:
|
||||
selection:
|
||||
EventID:
|
||||
- 5001
|
||||
- 5010
|
||||
- 5012
|
||||
- 5101
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Administrator actions
|
||||
level: high
|
22
rules/windows/other/win_defender_threat.yml
Normal file
22
rules/windows/other/win_defender_threat.yml
Normal file
@ -0,0 +1,22 @@
|
||||
title: Windows Defender Threat Detected
|
||||
id: 57b649ef-ff42-4fb0-8bf6-62da243a1708
|
||||
description: Detects all actions taken by Windows Defender malware detection engines
|
||||
date: 2020/07/28
|
||||
author: Ján Trenčanský
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus
|
||||
status: stable
|
||||
logsource:
|
||||
product: windows
|
||||
service: windefend
|
||||
detection:
|
||||
selection:
|
||||
EventID:
|
||||
- 1006
|
||||
- 1116
|
||||
- 1015
|
||||
- 1117
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unlikely
|
||||
level: high
|
@ -43,4 +43,9 @@ logsources:
|
||||
service: dhcp
|
||||
conditions:
|
||||
Channel: 'Microsoft-Windows-DHCP-Server/Operational'
|
||||
windows-defender:
|
||||
product: windows
|
||||
service: windefend
|
||||
conditions:
|
||||
Channel: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
defaultindex: logstash-*
|
||||
|
@ -69,3 +69,8 @@ logsources:
|
||||
service: dhcp
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-DHCP-Server/Operational'
|
||||
windows-defender:
|
||||
product: windows
|
||||
service: windefend
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
|
@ -44,6 +44,11 @@ logsources:
|
||||
service: dhcp
|
||||
conditions:
|
||||
winlog.provider_name: 'Microsoft-Windows-DHCP-Server/Operational'
|
||||
windows-defender:
|
||||
product: windows
|
||||
service: windefend
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
defaultindex: winlogbeat-*
|
||||
# Extract all field names qith yq:
|
||||
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g'
|
||||
|
@ -43,6 +43,11 @@ logsources:
|
||||
service: dhcp
|
||||
conditions:
|
||||
source: 'Microsoft-Windows-DHCP-Server/Operational'
|
||||
windows-defender:
|
||||
product: windows
|
||||
service: windefend
|
||||
conditions:
|
||||
source: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
defaultindex: winlogbeat-*
|
||||
# Extract all field names qith yq:
|
||||
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: event_data.\1/g'
|
||||
|
@ -43,6 +43,11 @@ logsources:
|
||||
service: dhcp
|
||||
conditions:
|
||||
winlog.provider_name: 'Microsoft-Windows-DHCP-Server/Operational'
|
||||
windows-defender:
|
||||
product: windows
|
||||
service: windefend
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
defaultindex: winlogbeat-*
|
||||
# Extract all field names qith yq:
|
||||
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g'
|
||||
|
Loading…
Reference in New Issue
Block a user