下载地址 : https://download.sysinternals.com/files/Sysmon.zip
Install: Sysmon.exe -i <configfile> # 指定配置文件安装
sysmon -accepteula –i -n # 一键安装(使用sha1进行散列的过程映像,无网络监控)
sysmon -accepteula -i -h md5,sha256 -n # 使用md5和sha256进行安装创建进程并监视网络连接
sysmon -accepteula -i c\windows\config.xml # 使用配置文件安装Sysmon
[-h <[sha1|md5|sha256|imphash|*],...>] [-n [<process,...>]]
[-l (<process,...>)]
Configure: Sysmon.exe -c <configfile> # 从文件读取修改配置信息
sysmon –c -- # 修改配置信息为默认配置
sysmon -c # 转储配置文件
[--|[-h <[sha1|md5|sha256|imphash|*],...>] [-n [<process,...>]]
[-l [<process,...>]]]
Uninstall: Sysmon.exe -u # 卸载
# 注 : 安装需要管理员权限 操作系统 windows 7+ 上日志会写入到 Logs/Microsoft/Windows/Sysmon/Operational 低版本windows 会写入到 system日志
-d # 指定已安装设备驱动程序映像的名称。
-c # 更新或显示配置 如果没有提供其他参数,则为当前配置。可选获取配置文件。
-h # 指定hash记录的算法
-i # 安装,可用xml文件来更新配置文件
-l # 记录加载模块,可指定进程
-m # 安装事件清单
-n # 记录网络链接
-r # 检测证书是否撤销
-u # 卸载服务和驱动
-s # 打印配置架构
-? config # 查看配置文件写法
配置文件说明
<Sysmon schemaversion="4.21">
<HashAlgorithms>*HashAlgorithms>
<EventFiltering>
<DriverLoad onmatch="exclude">
<Signature condition="contains">microsoftSignature>
<Signature condition="contains">windowsSignature>
DriverLoad>
<ProcessTerminate onmatch="include" />
<NetworkConnect onmatch="include">
<DestinationPort>443DestinationPort>
<DestinationPort>80DestinationPort>
NetworkConnect>
<NetworkConnect onmatch="exclude">
<Image condition="end with">iexplore.exeImage>
NetworkConnect>
EventFiltering>
Sysmon>
-- 配置条目直接位于Sysmon 标签下, 过滤器位于 EventFiltering 标签下
ProcessCreate 进程创建
FileCreateTime 文件创建时间更改
NetworkConnect 检测到网络连接
ProcessTerminate 进程终止
DriverLoad 驱动程序已加载
ImageLoad 镜像加载
CreateRemoteThread 已检测到创建远程线程
RawAccessRead 检测到原始访问读取
ProcessAccess 已访问的进程
FileCreate 文件创建
RegistryEvent 添加或删除注册表对象
RegistryEvent 注册表值设置
RegistryEvent 注册表对象已重命名
FileCreateStreamHash 已创建文件流
PipeEvent 管道创建
PipeEvent 管道已连接
WmiEvent 检测到WmiEventFilter活动 -- WmiEventFilter activity detected
WmiEvent 检测到WmiEventConsumer活动 -- WmiEventConsumer activity detected
WmiEvent 检测到WmiEventConsumerToFilter活动 -- WmiEventConsumerToFilter activity
DnsQuery DNS查询
使用onmacth标记配置文件中 过滤器规则 include exclude
include:
仅包含include的规则配置
exclude:
除去该规则配置, 其他全包含
PS:
例如,此规则将丢弃进程创建中 IntegrityLevel 为中等的任何流程事件
Medium
--------------------------------------
注: 不区分大小写
--------------------------------------
字段如下:
is 默认值, 等于
is not 不等于
contains 包含
excludes 不包含
begin with 以此字段开始
end with 以此字段结束
less than 小于
more than 大于
image 匹配镜像路径(完整路径或仅镜像名称)
例如:lsass.exe将匹配c:\windows\system32\lsass.exe
-----------------------------------------
<EventFiltering>
<RuleGroup name="group 1" groupRelation="and">
<ProcessCreate onmatch="include">
<Image condition="contains">timeout.exeImage>
<CommandLine condition="contains">100CommandLine>
ProcessCreate>
RuleGroup>
<RuleGroup groupRelation="or">
<ProcessTerminate onmatch="include">
<Image condition="contains">timeout.exeImage>
<Image condition="contains">ping.exeImage>
ProcessTerminate>
RuleGroup>
<ImageLoad onmatch="include"/>
EventFiltering>
要让sysmon报告哪个规则匹配导致记录事件,请向规则添加名称:
<NetworkConnect onmatch="exclude">
<Image name="network iexplore" condition="contains">iexplore.exeImage>
NetworkConnect>
<Sysmon schemaversion="4.21">
<HashAlgorithms>md5,sha256HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="exclude">
<ParentCommandLine condition="is">"C:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe" -EmbeddingParentCommandLine>
<CommandLine condition="is"> "whoami" CommandLine>
<CommandLine condition="is"> "systeminfo" CommandLine>
<CommandLine condition="begin with"> "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" CommandLine>
<CommandLine condition="begin with">C:\Windows\system32\DllHost.exe /ProcessidCommandLine>
<CommandLine condition="begin with">C:\Windows\system32\wbem\wmiprvse.exe -EmbeddingCommandLine>
<CommandLine condition="begin with">C:\Windows\system32\wbem\wmiprvse.exe -secured -EmbeddingCommandLine>
<CommandLine condition="is">C:\Windows\system32\wermgr.exe -uploadCommandLine>
<CommandLine condition="is">C:\Windows\system32\SearchIndexer.exe /EmbeddingCommandLine>
<CommandLine condition="is">C:\windows\system32\wermgr.exe -queuereportingCommandLine>
<CommandLine condition="is">\??\C:\Windows\system32\autochk.exe *CommandLine>
<CommandLine condition="is">\SystemRoot\System32\smss.exeCommandLine>
<CommandLine condition="is">C:\Windows\System32\RuntimeBroker.exe -EmbeddingCommandLine>
<Image condition="is">C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exeImage>
<Image condition="is">C:\Windows\System32\TokenBrokerCookies.exeImage>
<Image condition="is">C:\Windows\System32\plasrv.exeImage>
<Image condition="is">C:\Windows\System32\wifitask.exeImage>
<Image condition="is">C:\Windows\system32\CompatTelRunner.exeImage>
<Image condition="is">C:\Windows\system32\PrintIsolationHost.exeImage>
<Image condition="is">C:\Windows\system32\SppExtComObj.ExeImage>
<Image condition="is">C:\Windows\system32\audiodg.exeImage>
<Image condition="is">C:\Windows\system32\conhost.exeImage>
<Image condition="is">C:\Windows\system32\mobsync.exeImage>
<Image condition="is">C:\Windows\system32\musNotification.exeImage>
<Image condition="is">C:\Windows\system32\musNotificationUx.exeImage>
<Image condition="is">C:\Windows\system32\powercfg.exeImage>
<Image condition="is">C:\Windows\system32\sndVol.exeImage>
<Image condition="is">C:\Windows\system32\sppsvc.exeImage>
<Image condition="is">C:\Windows\system32\wbem\WmiApSrv.exeImage>
<IntegrityLevel condition="is">AppContainerIntegrityLevel>
<ParentCommandLine condition="begin with">%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\WindowsParentCommandLine>
<ParentCommandLine condition="is">C:\windows\system32\wermgr.exe -queuereportingParentCommandLine>
<CommandLine condition="is">C:\WINDOWS\system32\devicecensus.exe UserCxtCommandLine>
<CommandLine condition="is">C:\Windows\System32\usocoreworker.exe -EmbeddingCommandLine>
<ParentImage condition="is">C:\Windows\system32\SearchIndexer.exeParentImage>
<Image condition="begin with">C:\Program Files\Windows DefenderImage>
<Image condition="is">C:\Windows\system32\MpSigStub.exeImage>
<CommandLine condition="is">C:\WINDOWS\System32\svchost.exe -k SafeMonorCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -s StateRepositoryCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -p -s camsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodelCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -p -s tiledatamodelsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k camera -s FrameServerCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k dcomlaunch -s LSMCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlayCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k defragsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k imgsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s EventSystemCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s bthservCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k LocalService -p -s BthAvctpSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s nsiCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s w32TimeCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonationCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s DhcpCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLogCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -s BTAGServiceCommandLine>
<CommandLine condition="is">C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestrictedCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p -s SSDPSRVCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNoNetworkCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnumCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnumCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvrCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauservCommandLine>
<CommandLine condition="is">C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnvCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHostCommandLine>
<CommandLine condition="is">C:\Windows\System32\svchost.exe -k localSystemNetworkRestricted -p -s WdiSystemHostCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestrictedCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s BDESVCCommandLine>
<CommandLine condition="is">C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVCCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s BITSCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s BITSCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s AppinfoCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s GpsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s SENSCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnvCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s ThemesCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s WinmgmtCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcsCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -p -s DoSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s DnscacheCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstationCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s NlaSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s TermServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkServiceCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkServiceNetworkRestrictedCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k rPCSSCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k secsvcsCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k swprvCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k unistackSvcGroupCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k utcsvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wbioSvcGroupCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k werSvcGroupCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvcCommandLine>
<CommandLine condition="is">C:\Windows\System32\svchost.exe -k wsappx -p -s ClipSVCCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvcCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappx -s ClipSVCCommandLine>
<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappxCommandLine>
<ParentCommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcsParentCommandLine>
<ParentCommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestrictedParentCommandLine>
<CommandLine condition="is">C:\Windows\system32\deviceenroller.exe /c /AutoEnrollMDMCommandLine>
<CommandLine condition="begin with">"C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe" --type=CommandLine>
<CommandLine condition="begin with">C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeCommandLine>
<CommandLine condition="begin with">C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\Ngen.exeCommandLine>
<Image condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exeImage>
<Image condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exeImage>
<Image condition="is">C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exeImage>
<ParentCommandLine condition="contains">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exeParentCommandLine>
<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exeParentImage>
<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exeParentImage>
<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exeParentImage>
<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exeParentImage>
<Image condition="is">C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXEImage>
<Image condition="is">C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEImage>
<Image condition="is">C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXEImage>
<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXEImage>
<Image condition="is">C:\Program Files\Microsoft Office\Office16\msoia.exeImage>
<Image condition="is">C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exeImage>
<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeImage>
<ParentImage condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exeParentImage>
<ParentImage condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeParentImage>
<Image condition="is">C:\Program Files\Windows Media Player\wmpnscfg.exeImage>
<CommandLine condition="begin with">"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=CommandLine>
<CommandLine condition="begin with">"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=CommandLine>
<CommandLine condition="begin with">"C:\Program Files\Mozilla Firefox\plugin-container.exe" --channelCommandLine>
<CommandLine condition="begin with">"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channelCommandLine>
<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exeParentImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\LogTransport2.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\AcroCEF\AcroCEF.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\LogTransport2.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\LogTransport2.exeImage>
<CommandLine condition="begin with">"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" /CR CommandLine>
<CommandLine condition="begin with">"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=CommandLine>
<Image condition="is">C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exeImage>
<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exeParentImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exeImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exeImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exeImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exeImage>
<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exeParentImage>
<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exeImage>
<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exeParentImage>
<Image condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exeImage>
<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exeParentImage>
<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exeParentImage>
<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exeParentImage>
<ParentImage condition="is">C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\agent.exeParentImage>
<CommandLine condition="is">C:\Windows\system32\igfxsrvc.exe -EmbeddingCommandLine>
<ParentImage condition="is">C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exeParentImage>
ProcessCreate>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileCreateTime onmatch="include">
<Image name="T1099" condition="begin with">C:\UsersImage>
<TargetFilename name="T1099" condition="end with">.exeTargetFilename>
<Image name="T1099" condition="begin with">\Device\HarddiskVolumeShadowCopyImage>
FileCreateTime>
<FileCreateTime onmatch="exclude">
<Image condition="image">OneDrive.exeImage>
<Image condition="image">C:\Windows\system32\backgroundTaskHost.exeImage>
<Image condition="contains">setupImage>
<Image condition="contains">installImage>
<Image condition="contains">Update\Image>
<Image condition="end with">redist.exeImage>
<Image condition="is">msiexec.exeImage>
<Image condition="is">TrustedInstaller.exeImage>
FileCreateTime>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<NetworkConnect onmatch="include">
<Image name="Usermode" condition="begin with">C:\UsersImage>
<Image name="Caution!" condition="begin with">C:\RecyleImage>
<Image condition="begin with">C:\ProgramDataImage>
<Image condition="begin with">C:\Windows\TempImage>
<Image name="Caution!" condition="begin with">\Image>
<Image name="Caution!" condition="begin with">C:\perflogsImage>
<Image name="Caution!" condition="begin with">C:\intelImage>
<Image name="Caution!" condition="begin with">C:\Windows\fontsImage>
<Image name="Caution!" condition="begin with">C:\Windows\system32\configImage>
<Image condition="image">at.exeImage>
<Image condition="image">certutil.exeImage>
<Image condition="image">cmd.exeImage>
<Image condition="image">cmstp.exeImage>
<Image condition="image">cscript.exeImage>
<Image condition="image">driverquery.exeImage>
<Image condition="image">dsquery.exeImage>
<Image condition="image">hh.exeImage>
<Image condition="image">infDefaultInstall.exeImage>
<Image condition="image">java.exeImage>
<Image condition="image">javaw.exeImage>
<Image condition="image">javaws.exeImage>
<Image condition="image">mmc.exeImage>
<Image condition="image">msbuild.exeImage>
<Image condition="image">mshta.exeImage>
<Image condition="image">msiexec.exeImage>
<Image condition="image">nbtstat.exeImage>
<Image condition="image">net.exeImage>
<Image condition="image">net1.exeImage>
<Image condition="image">notepad.exeImage>
<Image condition="image">nslookup.exeImage>
<Image condition="image">powershell.exeImage>
<Image condition="image">qprocess.exeImage>
<Image condition="image">qwinsta.exeImage>
<Image condition="image">qwinsta.exeImage>
<Image condition="image">reg.exeImage>
<Image condition="image">regsvcs.exeImage>
<Image condition="image">regsvr32.exeImage>
<Image condition="image">rundll32.exeImage>
<Image condition="image">rwinsta.exeImage>
<Image condition="image">sc.exeImage>
<Image condition="image">schtasks.exeImage>
<Image condition="image">taskkill.exeImage>
<Image condition="image">tasklist.exeImage>
<Image condition="image">wmic.exeImage>
<Image condition="image">wscript.exeImage>
<Image condition="image">nc.exeImage>
<Image condition="image">ncat.exeImage>
<Image condition="image">psexec.exeImage>
<Image condition="image">psexesvc.exeImage>
<Image condition="image">tor.exeImage>
<Image condition="image">vnc.exeImage>
<Image condition="image">vncservice.exeImage>
<Image condition="image">vncviewer.exeImage>
<Image condition="image">winexesvc.exeImage>
<Image condition="image">nmap.exeImage>
<Image condition="image">psinfo.exeImage>
<Image condition="image">bitsadmin.exeImage>
<DestinationPort name="CVE-2017-11882" condition="is">587DestinationPort>
<DestinationPort name="SMB" condition="is">139DestinationPort>
<DestinationPort name="SMB" condition="is">445DestinationPort>
<DestinationPort name="RPC" condition="is">135DestinationPort>
<DestinationPort name="DNS" condition="is">53DestinationPort>
<DestinationPort name="HTTPS" condition="is">443DestinationPort>
<DestinationPort name="FTP" condition="is">21DestinationPort>
<DestinationPort name="SSH" condition="is">22DestinationPort>
<DestinationPort name="Telnet" condition="is">23DestinationPort>
<DestinationPort name="SMTP" condition="is">25DestinationPort>
<DestinationPort name="IMAP" condition="is">142DestinationPort>
<DestinationPort name="RDP" condition="is">3389DestinationPort>
<DestinationPort name="VNC" condition="is">5800DestinationPort>
<DestinationPort name="VNC" condition="is">5900DestinationPort>
<DestinationPort name="Alert,Metasploit" condition="begin with">4444DestinationPort>
<DestinationPort name="Alert,Metasploit" condition="begin with">4445DestinationPort>
<DestinationPort name="Alert,Metasploit" condition="begin with">4446DestinationPort>
<DestinationPort name="Alert,Metasploit" condition="end with">1337DestinationPort>
<DestinationPort name="Proxy" condition="is">1080DestinationPort>
<DestinationPort name="Proxy" condition="is">3128DestinationPort>
<DestinationPort name="Proxy" condition="is">8080DestinationPort>
<DestinationPort name="Tor" condition="is">1723DestinationPort>
<DestinationPort name="Tor/IPsec" condition="is">4500DestinationPort>
<DestinationPort name="Tor" condition="is">9001DestinationPort>
<DestinationPort name="Tor" condition="is">9030DestinationPort>
NetworkConnect>
<NetworkConnect onmatch="exclude">
<Image condition="end with">AppData\Roaming\Dropbox\bin\Dropbox.exeImage>
<Image condition="end with">AppData\Local\Microsoft\Teams\current\Teams.exeImage>
<Image condition="end with">AppData\Roaming\Spotify\Spotify.exeImage>
<Image condition="end with">AppData\Local\Microsoft\Teams\current\Teams.exeImage>
<DestinationHostname condition="end with">.microsoft.comDestinationHostname>
<DestinationHostname condition="end with">microsoft.com.akadns.netDestinationHostname>
<DestinationHostname condition="end with">microsoft.com.nsatc.netDestinationHostname>
NetworkConnect>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<ProcessTerminate onmatch="include">
<Image condition="begin with">C:\UsersImage>
<Image condition="begin with">\Image>
ProcessTerminate>
<ProcessTerminate onmatch="exclude">
ProcessTerminate>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<DriverLoad onmatch="exclude">
<Signature condition="contains">microsoftSignature>
<Signature condition="contains">windowsSignature>
<Signature condition="begin with">Intel Signature>
DriverLoad>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<ImageLoad onmatch="include">
ImageLoad>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<CreateRemoteThread onmatch="exclude">
<SourceImage condition="is">C:\Windows\system32\wbem\WmiPrvSE.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\svchost.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\wininit.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\csrss.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\services.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\winlogon.exeSourceImage>
<SourceImage condition="is">C:\Windows\system32\audiodg.exeSourceImage>
<StartModule condition="is">C:\Windows\system32\kernel32.dllStartModule>
<TargetImage condition="is">C:\Program Files (x86)\Google\Chrome\Application\chrome.exeTargetImage>
CreateRemoteThread>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<RawAccessRead onmatch="include">
RawAccessRead>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<ProcessAccess onmatch="include">
ProcessAccess>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileCreate onmatch="include">
<TargetFilename name="T1023" condition="contains">\Start MenuTargetFilename>
<TargetFilename name="T1165" condition="contains">\Startup\TargetFilename>
<TargetFilename condition="contains">\Content.Outlook\TargetFilename>
<TargetFilename name="FileCreate-Downloads" condition="contains">\Downloads\TargetFilename>
<TargetFilename condition="end with">.applicationTargetFilename>
<TargetFilename condition="end with">.appref-msTargetFilename>
<TargetFilename condition="end with">.batTargetFilename>
<TargetFilename condition="end with">.chmTargetFilename>
<TargetFilename condition="end with">.cmdTargetFilename>
<TargetFilename condition="end with">.cmdlineTargetFilename>
<TargetFilename name="T1176" condition="end with">.crxTargetFilename>
<TargetFilename condition="end with">.docmTargetFilename>
<TargetFilename condition="end with">.dllTargetFilename>
<TargetFilename condition="end with">.exeTargetFilename>
<TargetFilename condition="end with">.jarTargetFilename>
<TargetFilename condition="end with">.jnlpTargetFilename>
<TargetFilename condition="end with">.jseTargetFilename>
<TargetFilename condition="end with">.htaTargetFilename>
<TargetFilename condition="end with">.pptmTargetFilename>
<TargetFilename condition="end with">.ps1TargetFilename>
<TargetFilename condition="end with">.sysTargetFilename>
<TargetFilename condition="end with">.scrTargetFilename>
<TargetFilename condition="end with">.vbeTargetFilename>
<TargetFilename condition="end with">.vbsTargetFilename>
<TargetFilename condition="end with">.xlsmTargetFilename>
<TargetFilename condition="end with">projTargetFilename>
<TargetFilename condition="end with">.slnTargetFilename>
<TargetFilename condition="begin with">C:\Users\DefaultTargetFilename>
<TargetFilename condition="begin with">C:\Windows\system32\DriversTargetFilename>
<TargetFilename condition="begin with">C:\Windows\SysWOW64\DriversTargetFilename>
<TargetFilename name="T1037,T1484" condition="begin with">C:\Windows\system32\GroupPolicy\Machine\ScriptsTargetFilename>
<TargetFilename name="T1037,T1484" condition="begin with">C:\Windows\system32\GroupPolicy\User\ScriptsTargetFilename>
<TargetFilename condition="begin with">C:\Windows\system32\WbemTargetFilename>
<TargetFilename condition="begin with">C:\Windows\SysWOW64\WbemTargetFilename>
<TargetFilename condition="begin with">C:\Windows\system32\WindowsPowerShellTargetFilename>
<TargetFilename condition="begin with">C:\Windows\SysWOW64\WindowsPowerShellTargetFilename>
<TargetFilename name="T1053" condition="begin with">C:\Windows\Tasks\TargetFilename>
<TargetFilename name="T1053" condition="begin with">C:\Windows\system32\TasksTargetFilename>
<Image condition="begin with">\Device\HarddiskVolumeShadowCopyImage>
<TargetFilename condition="begin with">C:\Windows\AppPatch\CustomTargetFilename>
<TargetFilename condition="contains">VirtualStoreTargetFilename>
<TargetFilename condition="end with">.xlsTargetFilename>
<TargetFilename condition="end with">.pptTargetFilename>
<TargetFilename condition="end with">.rtfTargetFilename>
FileCreate>
<FileCreate onmatch="exclude">
<Image condition="is">C:\Program Files (x86)\EMET 5.5\EMET_Service.exeImage>
<TargetFilename condition="is">C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTaskTargetFilename>
<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeImage>
<Image condition="is">C:\Windows\system32\smss.exeImage>
<Image condition="is">C:\Windows\system32\CompatTelRunner.exeImage>
<Image condition="is">\\?\C:\Windows\system32\wbem\WMIADAP.EXEImage>
<Image condition="is">C:\Windows\system32\mobsync.exeImage>
<TargetFilename condition="begin with">C:\Windows\system32\DriverStore\Temp\TargetFilename>
<TargetFilename condition="begin with">C:\Windows\system32\wbem\Performance\TargetFilename>
<TargetFilename condition="end with">WRITABLE.TSTTargetFilename>
<TargetFilename condition="begin with">C:\Windows\Installer\TargetFilename>
<TargetFilename condition="begin with">C:\$WINDOWS.~BT\Sources\TargetFilename>
<Image condition="begin with">C:\Windows\winsxs\amd64_microsoft-windowsImage>
<Image condition="is">C:\Windows\system32\igfxCUIService.exeImage>
FileCreate>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<RegistryEvent onmatch="include">
<TargetObject name="T1060,RunKey" condition="contains">CurrentVersion\RunTargetObject>
<TargetObject name="T1060,RunPolicy" condition="contains">Policies\Explorer\RunTargetObject>
<TargetObject name="T1484" condition="contains">Group Policy\ScriptsTargetObject>
<TargetObject name="T1484" condition="contains">Windows\System\ScriptsTargetObject>
<TargetObject name="T1060" condition="contains">CurrentVersion\Windows\LoadTargetObject>
<TargetObject name="T1060" condition="contains">CurrentVersion\Windows\RunTargetObject>
<TargetObject name="T1060" condition="contains">CurrentVersion\Winlogon\ShellTargetObject>
<TargetObject name="T1060" condition="contains">CurrentVersion\Winlogon\SystemTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\NotifyTargetObject>
<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ShellTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserinitTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32TargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecuteTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebugTargetObject>
<TargetObject condition="contains">UserInitMprLogonScriptTargetObject>
<TargetObject name="T1112,ChangeStartupFolderPath" condition="end with">user shell folders\startupTargetObject>
<TargetObject name="T1031,T1050" condition="end with">\ServiceDllTargetObject>
<TargetObject name="T1031,T1050" condition="end with">\ServiceManifestTargetObject>
<TargetObject name="T1031,T1050" condition="end with">\ImagePathTargetObject>
<TargetObject name="T1031,T1050" condition="end with">\StartTargetObject>
<TargetObject name="RDP port change" condition="end with">Control\Terminal Server\WinStations\RDP-Tcp\PortNumberTargetObject>
<TargetObject name="RDP port change" condition="end with">Control\Terminal Server\fSingleSessionPerUserTargetObject>
<TargetObject name="ModifyRemoteDesktopState" condition="end with">fDenyTSConnectionsTargetObject>
<TargetObject condition="end with">LastLoggedOnUserTargetObject>
<TargetObject name="ModifyRemoteDesktopPort" condition="end with">RDP-tcp\PortNumberTargetObject>
<TargetObject condition="end with">Services\PortProxy\v4tov4TargetObject>
<TargetObject name="T1042" condition="contains">\command\TargetObject>
<TargetObject name="T1122" condition="contains">\ddeexec\TargetObject>
<TargetObject name="T1122" condition="contains">{86C86720-42A0-1069-A2E8-08002B30309D}TargetObject>
<TargetObject name="T1042" condition="contains">exefileTargetObject>
<TargetObject condition="end with">\InprocServer32\(Default)TargetObject>
<TargetObject name="T1158" condition="end with">\HiddenTargetObject>
<TargetObject name="T1158" condition="end with">\ShowSuperHiddenTargetObject>
<TargetObject name="T1158" condition="end with">\HideFileExtTargetObject>
<TargetObject condition="contains">Classes\*\TargetObject>
<TargetObject condition="contains">Classes\AllFilesystemObjects\TargetObject>
<TargetObject condition="contains">Classes\Directory\TargetObject>
<TargetObject condition="contains">Classes\Drive\TargetObject>
<TargetObject condition="contains">Classes\Folder\TargetObject>
<TargetObject condition="contains">ContextMenuHandlers\TargetObject>
<TargetObject condition="contains">CurrentVersion\ShellTargetObject>
<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooksTargetObject>
<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoadTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiersTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgramTargetObject>
<TargetObject name="T1484" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\TargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\WinSock\TargetObject>
<TargetObject condition="end with">\ProxyServerTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential ProviderTargetObject>
<TargetObject name="T1101" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\TargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProvidersTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\NetshTargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\TargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\ProfilesTargetObject>
<TargetObject name="T1089" condition="end with">\EnableFirewallTargetObject>
<TargetObject name="T1089" condition="end with">\DoNotAllowExceptionsTargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ListTargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ListTargetObject>
<TargetObject name="T1103" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\TargetObject>
<TargetObject name="T1103" condition="begin with">HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\TargetObject>
<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\TargetObject>
<TargetObject name="T1137" condition="contains">Microsoft\Office\Outlook\Addins\TargetObject>
<TargetObject name="T1137" condition="contains">Office Test\TargetObject>
<TargetObject name="Context,ProtectedModeExitOrMacrosUsed" condition="contains">Security\Trusted Documents\TrustRecordsTargetObject>
<TargetObject name="T1176" condition="contains">Internet Explorer\Toolbar\TargetObject>
<TargetObject name="T1176" condition="contains">Internet Explorer\Extensions\TargetObject>
<TargetObject name="T1176" condition="contains">Browser Helper Objects\TargetObject>
<TargetObject condition="end with">\DisableSecuritySettingsCheckTargetObject>
<TargetObject condition="end with">\3\1206TargetObject>
<TargetObject condition="end with">\3\2500TargetObject>
<TargetObject condition="end with">\3\1809TargetObject>
<TargetObject condition="contains">{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\TargetObject>
<TargetObject name="Alert,Sysinternals Tool Used" condition="end with">\EulaAcceptedTargetObject>
<TargetObject condition="end with">\UrlUpdateInfoTargetObject>
<TargetObject condition="end with">\InstallSourceTargetObject>
<TargetObject name="T1089,Tamper-Defender" condition="end with">\DisableAntiSpywareTargetObject>
<TargetObject name="T1089,Tamper-Defender" condition="end with">\DisableAntiVirusTargetObject>
<TargetObject name="T1088" condition="end with">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUATargetObject>
<TargetObject name="T1088" condition="end with">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicyTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AllAlertsDisabledTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverrideTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotifyTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\DisableMonitoringTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotifyTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverrideTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotifyTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotifyTargetObject>
<TargetObject name="T1089,Tamper-SecCenter" condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealthTargetObject>
<TargetObject name="T1138,AppCompatShim" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CustomTargetObject>
<TargetObject name="T1138,AppCompatShim" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDBTargetObject>
<TargetObject condition="contains">VirtualStoreTargetObject>
<TargetObject name="T1183,IFEO" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\TargetObject>
<TargetObject name="Tamper-Safemode" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\TargetObject>
<TargetObject name="Tamper-Winlogon" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\TargetObject>
<TargetObject name="Context,DeviceConntectedOrUpdated" condition="end with">\FriendlyNameTargetObject>
<TargetObject name="Context,MsiInstallerStarted" condition="is">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default)TargetObject>
<TargetObject name="Tamper-Tracing" condition="begin with">HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32TargetObject>
<TargetObject name="InvDB-Path" condition="end with">\LowerCaseLongPathTargetObject>
<TargetObject name="InvDB-Pub" condition="end with">\PublisherTargetObject>
<TargetObject name="InvDB-Ver" condition="end with">\ProductVersionTargetObject>
<TargetObject name="InvDB-CompileTimeClaim" condition="end with">\LinkDateTargetObject>
<TargetObject name="InvDB" condition="contains">Compatibility Assistant\Store\TargetObject>
<Image name="Suspicious,ImageBeginWithBackslash" condition="begin with">\Image>
RegistryEvent>
<RegistryEvent onmatch="exclude">
<TargetObject condition="begin with">HKLM\COMPONENTSTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\CacheTargetObject>
<TargetObject condition="end with">Toolbar\WebBrowserTargetObject>
<TargetObject condition="end with">Browser\ITBar7HeightTargetObject>
<TargetObject condition="end with">Browser\ITBar7LayoutTargetObject>
<TargetObject condition="end with">Internet Explorer\Toolbar\LockedTargetObject>
<TargetObject condition="end with">Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93}TargetObject>
<TargetObject condition="end with">}\PreviousPolicyAreasTargetObject>
<TargetObject condition="contains">\Control\WMI\Autologger\TargetObject>
<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\StartTargetObject>
<TargetObject condition="end with">\Lsa\OfflineJoin\CurrentValueTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\TargetObject>
<TargetObject condition="contains">_Classes\AppXTargetObject>
<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\TargetObject>
<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPidTargetObject>
<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCacheTargetObject>
<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\DomainsTargetObject>
<TargetObject condition="end with">\Services\BITS\StartTargetObject>
<TargetObject condition="end with">\services\clr_optimization_v2.0.50727_32\StartTargetObject>
<TargetObject condition="end with">\services\clr_optimization_v2.0.50727_64\StartTargetObject>
<TargetObject condition="end with">\services\clr_optimization_v4.0.30319_32\StartTargetObject>
<TargetObject condition="end with">\services\clr_optimization_v4.0.30319_64\StartTargetObject>
<TargetObject condition="end with">\services\deviceAssociationService\StartTargetObject>
<TargetObject condition="end with">\services\fhsvc\StartTargetObject>
<TargetObject condition="end with">\services\nal\StartTargetObject>
<TargetObject condition="end with">\services\trustedInstaller\StartTargetObject>
<TargetObject condition="end with">\services\tunnel\StartTargetObject>
<TargetObject condition="end with">\services\usoSvc\StartTargetObject>
<TargetObject condition="end with">\UserChoice\ProgIdTargetObject>
<TargetObject condition="end with">\UserChoice\HashTargetObject>
<TargetObject condition="end with">\OpenWithList\MRUListTargetObject>
<TargetObject condition="contains">Shell Extentions\CachedTargetObject>
<TargetObject condition="end with">HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroupsTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrderTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-IDTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-IDTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershellTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTimeTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrderTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-IDTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-IDTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershellTargetObject>
<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTimeTargetObject>
<TargetObject condition="contains">\safer\codeidentifiers\0\HASHES\{TargetObject>
<TargetObject condition="contains">VirtualStore\MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\TargetObject>
<Image condition="is">C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exeImage>
<TargetObject condition="begin with">HKCR\VLC.TargetObject>
<TargetObject condition="begin with">HKCR\iTunes.TargetObject>
<TargetObject condition="is">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{945a8954-c147-4acd-923f-40c45405a658}TargetObject>
RegistryEvent>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileCreateStreamHash onmatch="include">
<TargetFilename name="FileStream-Downloads" condition="contains">DownloadsTargetFilename>
<TargetFilename condition="contains">Temp\7zTargetFilename>
<TargetFilename condition="contains">StartupTargetFilename>
<TargetFilename condition="end with">.batTargetFilename>
<TargetFilename condition="end with">.cmdTargetFilename>
<TargetFilename condition="end with">.htaTargetFilename>
<TargetFilename condition="end with">.lnkTargetFilename>
<TargetFilename condition="end with">.ps1TargetFilename>
<TargetFilename condition="end with">.ps2TargetFilename>
<TargetFilename condition="end with">.regTargetFilename>
<TargetFilename condition="end with">.jseTargetFilename>
<TargetFilename condition="end with">.vbTargetFilename>
<TargetFilename condition="end with">.vbeTargetFilename>
<TargetFilename condition="end with">.vbsTargetFilename>
FileCreateStreamHash>
<FileCreateStreamHash onmatch="exclude">
FileCreateStreamHash>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<PipeEvent onmatch="include">
PipeEvent>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<WmiEvent onmatch="exclude">
WmiEvent>
RuleGroup>
<RuleGroup name="" groupRelation="or">
<DnsQuery onmatch="exclude">
<QueryName condition="end with">.arpa.QueryName>
<QueryName condition="end with">.arpaQueryName>
<QueryName condition="end with">.msftncsi.comQueryName>
<QueryName condition="is">..localmachineQueryName>
<QueryName condition="end with">-pushp.svc.msQueryName>
<QueryName condition="end with">.b-msedge.netQueryName>
<QueryName condition="end with">.bing.comQueryName>
<QueryName condition="end with">.hotmail.comQueryName>
<QueryName condition="end with">.live.comQueryName>
<QueryName condition="end with">.live.netQueryName>
<QueryName condition="end with">.s-microsoft.comQueryName>
<QueryName condition="end with">.microsoft.comQueryName>
<QueryName condition="end with">.microsoftonline.comQueryName>
<QueryName condition="end with">.microsoftstore.comQueryName>
<QueryName condition="end with">.ms-acdc.office.comQueryName>
<QueryName condition="end with">.msedge.netQueryName>
<QueryName condition="end with">.msn.comQueryName>
<QueryName condition="end with">.msocdn.comQueryName>
<QueryName condition="end with">.skype.comQueryName>
<QueryName condition="end with">.skype.netQueryName>
<QueryName condition="end with">.windows.comQueryName>
<QueryName condition="end with">.windows.net.nsatc.netQueryName>
<QueryName condition="end with">.windowsupdate.comQueryName>
<QueryName condition="end with">.xboxlive.comQueryName>
<QueryName condition="is">login.windows.netQueryName>
<QueryName condition="end with">.activedirectory.windowsazure.comQueryName>
<QueryName condition="end with">.aria.microsoft.comQueryName>
<QueryName condition="end with">.msauth.netQueryName>
<QueryName condition="end with">.msftauth.netQueryName>
<QueryName condition="end with">.opinsights.azure.comQueryName>
<QueryName condition="is">management.azure.comQueryName>
<QueryName condition="is">outlook.office365.comQueryName>
<QueryName condition="is">portal.azure.comQueryName>
<QueryName condition="end with">.mozaws.netQueryName>
<QueryName condition="end with">.mozilla.comQueryName>
<QueryName condition="end with">.mozilla.netQueryName>
<QueryName condition="end with">.mozilla.orgQueryName>
<QueryName condition="end with">.spotify.comQueryName>
<QueryName condition="end with">.spotify.map.fastly.netQueryName>
<QueryName condition="is">clients1.google.comQueryName>
<QueryName condition="is">clients2.google.comQueryName>
<QueryName condition="is">clients3.google.comQueryName>
<QueryName condition="is">clients4.google.comQueryName>
<QueryName condition="is">clients5.google.comQueryName>
<QueryName condition="is">clients6.google.comQueryName>
<QueryName condition="is">safebrowsing.googleapis.comQueryName>
<QueryName condition="end with">.akadns.netQueryName>
<QueryName condition="end with">.netflix.comQueryName>
<QueryName condition="end with">aspnetcdn.comQueryName>
<QueryName condition="is">ajax.googleapis.comQueryName>
<QueryName condition="is">cdnjs.cloudflare.comQueryName>
<QueryName condition="is">fonts.googleapis.comQueryName>
<QueryName condition="end with">.typekit.netQueryName>
<QueryName condition="is">cdnjs.cloudflare.comQueryName>
<QueryName condition="end with">.steamcontent.comQueryName>
<QueryName condition="end with">.disqus.comQueryName>
<QueryName condition="end with">.fontawesome.comQueryName>
<QueryName condition="is">disqus.comQueryName>
<QueryName condition="end with">.2mdn.netQueryName>
<QueryName condition="end with">.adadvisor.netQueryName>
<QueryName condition="end with">.adap.tvQueryName>
<QueryName condition="end with">.addthis.comQueryName>
<QueryName condition="end with">.adform.netQueryName>
<QueryName condition="end with">.adnxs.comQueryName>
<QueryName condition="end with">.adroll.comQueryName>
<QueryName condition="end with">.adsafeprotected.comQueryName>
<QueryName condition="end with">.adsrvr.orgQueryName>
<QueryName condition="end with">.advertising.comQueryName>
<QueryName condition="end with">.amazon-adsystem.comQueryName>
<QueryName condition="end with">.amazon-adsystem.comQueryName>
<QueryName condition="end with">.analytics.yahoo.comQueryName>
<QueryName condition="end with">.aol.comQueryName>
<QueryName condition="end with">.betrad.comQueryName>
<QueryName condition="end with">.bidswitch.netQueryName>
<QueryName condition="end with">.casalemedia.comQueryName>
<QueryName condition="end with">.chartbeat.netQueryName>
<QueryName condition="end with">.cnn.comQueryName>
<QueryName condition="end with">.convertro.comQueryName>
<QueryName condition="end with">.criteo.comQueryName>
<QueryName condition="end with">.criteo.netQueryName>
<QueryName condition="end with">.crwdcntrl.netQueryName>
<QueryName condition="end with">.demdex.netQueryName>
<QueryName condition="end with">.domdex.comQueryName>
<QueryName condition="end with">.dotomi.comQueryName>
<QueryName condition="end with">.doubleclick.netQueryName>
<QueryName condition="end with">.doubleverify.comQueryName>
<QueryName condition="end with">.emxdgt.comQueryName>
<QueryName condition="end with">.exelator.comQueryName>
<QueryName condition="end with">.google-analytics.comQueryName>
<QueryName condition="end with">.googleadservices.comQueryName>
<QueryName condition="end with">.googlesyndication.comQueryName>
<QueryName condition="end with">.googletagmanager.comQueryName>
<QueryName condition="end with">.googlevideo.comQueryName>
<QueryName condition="end with">.gstatic.comQueryName>
<QueryName condition="end with">.gvt1.comQueryName>
<QueryName condition="end with">.gvt2.comQueryName>
<QueryName condition="end with">.ib-ibi.comQueryName>
<QueryName condition="end with">.jivox.comQueryName>
<QueryName condition="end with">.mathtag.comQueryName>
<QueryName condition="end with">.moatads.comQueryName>
<QueryName condition="end with">.moatpixel.comQueryName>
<QueryName condition="end with">.mookie1.comQueryName>
<QueryName condition="end with">.myvisualiq.netQueryName>
<QueryName condition="end with">.netmng.comQueryName>
<QueryName condition="end with">.nexac.comQueryName>
<QueryName condition="end with">.nexac.comQueryName>
<QueryName condition="end with">.openx.netQueryName>
<QueryName condition="end with">.optimizely.comQueryName>
<QueryName condition="end with">.outbrain.comQueryName>
<QueryName condition="end with">.pardot.comQueryName>
<QueryName condition="end with">.phx.gblQueryName>
<QueryName condition="end with">.pinterest.comQueryName>
<QueryName condition="end with">.pubmatic.comQueryName>
<QueryName condition="end with">.quantcount.comQueryName>
<QueryName condition="end with">.quantserve.comQueryName>
<QueryName condition="end with">.revsci.netQueryName>
<QueryName condition="end with">.rfihub.netQueryName>
<QueryName condition="end with">.rlcdn.comQueryName>
<QueryName condition="end with">.rubiconproject.comQueryName>
<QueryName condition="end with">.scdn.coQueryName>
<QueryName condition="end with">.scorecardresearch.comQueryName>
<QueryName condition="end with">.serving-sys.comQueryName>
<QueryName condition="end with">.sharethrough.comQueryName>
<QueryName condition="end with">.simpli.fiQueryName>
<QueryName condition="end with">.sitescout.comQueryName>
<QueryName condition="end with">.smartadserver.comQueryName>
<QueryName condition="end with">.snapads.comQueryName>
<QueryName condition="end with">.spotxchange.comQueryName>
<QueryName condition="end with">.1rx.ioQueryName>
<QueryName condition="end with">.adrta.comQueryName>
<QueryName condition="end with">.taboola.comQueryName>
<QueryName condition="end with">.taboola.map.fastly.netQueryName>
<QueryName condition="end with">.tapad.comQueryName>
<QueryName condition="end with">.tidaltv.comQueryName>
<QueryName condition="end with">.trafficmanager.netQueryName>
<QueryName condition="end with">.tremorhub.comQueryName>
<QueryName condition="end with">.tribalfusion.comQueryName>
<QueryName condition="end with">.turn.comQueryName>
<QueryName condition="end with">.twimg.comQueryName>
<QueryName condition="end with">.tynt.comQueryName>
<QueryName condition="end with">.w55c.netQueryName>
<QueryName condition="end with">.ytimg.comQueryName>
<QueryName condition="end with">.zorosrv.comQueryName>
<QueryName condition="is">adservice.google.comQueryName>
<QueryName condition="is">ampcid.google.comQueryName>
<QueryName condition="is">clientservices.googleapis.comQueryName>
<QueryName condition="is">d29x207vrinatv.cloudfront.netQueryName>
<QueryName condition="is">googleadapis.l.google.comQueryName>
<QueryName condition="is">imasdk.googleapis.comQueryName>
<QueryName condition="is">l.google.comQueryName>
<QueryName condition="is">ml314.comQueryName>
<QueryName condition="is">mtalk.google.comQueryName>
<QueryName condition="is">update.googleapis.comQueryName>
<QueryName condition="is">1rx.ioQueryName>
<QueryName condition="is">www.googletagservices.comQueryName>
<QueryName condition="end with">.pscp.tvQueryName>
<QueryName condition="end with">.digicert.comQueryName>
<QueryName condition="end with">.globalsign.comQueryName>
<QueryName condition="end with">.globalsign.netQueryName>
<QueryName condition="is">msocsp.comQueryName>
<QueryName condition="is">ocsp.msocsp.comQueryName>
<QueryName condition="end with">pki.googQueryName>
<QueryName condition="is">ocsp.godaddy.comQueryName>
<QueryName condition="end with">amazontrust.comQueryName>
<QueryName condition="is">ocsp.sectigo.comQueryName>
<QueryName condition="is">pki-goog.l.google.comQueryName>
<QueryName condition="end with">.usertrust.comQueryName>
<QueryName condition="is">ocsp.comodoca.comQueryName>
<QueryName condition="is">ocsp.verisign.comQueryName>
<QueryName condition="is">ocsp.entrust.netQueryName>
<QueryName condition="end with">ocsp.identrust.comQueryName>
<QueryName condition="is">status.rapidssl.comQueryName>
<QueryName condition="is">status.thawte.comQueryName>
<QueryName condition="is">ocsp.int-x3.letsencrypt.orgQueryName>
DnsQuery>
RuleGroup>
EventFiltering>
Sysmon>
<Sysmon schemaversion="4.21">
<HashAlgorithms>*HashAlgorithms>
<CheckRevocation/>
<EventFiltering >
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="exclude">ProcessCreate>
<FileCreateTime onmatch="exclude">FileCreateTime>
<NetworkConnect onmatch="exclude">NetworkConnect>
<ProcessTerminate onmatch="exclude">ProcessTerminate>
<DriverLoad onmatch="exclude">DriverLoad>
<ImageLoad onmatch="exclude">ImageLoad>
<CreateRemoteThread onmatch="exclude">CreateRemoteThread>
<RawAccessRead onmatch="exclude">RawAccessRead>
<ProcessAccess onmatch="exclude">ProcessAccess>
<FileCreate onmatch="exclude">FileCreate>
<RegistryEvent onmatch="exclude">RegistryEvent>
<FileCreateStreamHash onmatch="exclude">FileCreateStreamHash>
<PipeEvent onmatch="exclude">PipeEvent>
<DnsQuery onmatch="exclude">DnsQuery>
RuleGroup>
EventFiltering>