关于sysmon的基本使用(1)

sysmon的基本使用(1)


  • 安装

     下载地址 :  https://download.sysinternals.com/files/Sysmon.zip
    
     Install:    Sysmon.exe -i <configfile> # 指定配置文件安装
                 sysmon -accepteula  –i -n # 一键安装(使用sha1进行散列的过程映像,无网络监控)
                 sysmon -accepteula -i -h md5,sha256 -n # 使用md5和sha256进行安装创建进程并监视网络连接
                 sysmon -accepteula -i c\windows\config.xml # 使用配置文件安装Sysmon
    
                 
    
    [-h <[sha1|md5|sha256|imphash|*],...>] [-n [<process,...>]]
    [-l (<process,...>)]
    
    Configure:  Sysmon.exe -c <configfile> # 从文件读取修改配置信息 
                sysmon –c -- # 修改配置信息为默认配置
                sysmon -c # 转储配置文件
                  [--|[-h <[sha1|md5|sha256|imphash|*],...>] [-n [<process,...>]]
                   [-l [<process,...>]]]
    
    Uninstall:  Sysmon.exe -u # 卸载 
     # 注 : 安装需要管理员权限 操作系统 windows 7+ 上日志会写入到  Logs/Microsoft/Windows/Sysmon/Operational 低版本windows 会写入到 system日志 
    

  • 参数说明
         -d # 指定已安装设备驱动程序映像的名称。
    
         -c  # 更新或显示配置 如果没有提供其他参数,则为当前配置。可选获取配置文件。
    
         -h  # 指定hash记录的算法
    
         -i  # 安装,可用xml文件来更新配置文件
    
         -l  # 记录加载模块,可指定进程
    
         -m  # 安装事件清单
    
         -n  # 记录网络链接
    
         -r  # 检测证书是否撤销
    
         -u  # 卸载服务和驱动
         
         -s  # 打印配置架构 
    
         -? config # 查看配置文件写法 
    

  • 配置文件说明

    • 官方给出的配置文件例子:
      <Sysmon schemaversion="4.21">
      
      <HashAlgorithms>*HashAlgorithms> 
      <EventFiltering> 
      
      
      <DriverLoad onmatch="exclude"> 
           <Signature condition="contains">microsoftSignature>
           <Signature condition="contains">windowsSignature>
      DriverLoad>
      
      
      <ProcessTerminate onmatch="include" />
      
      
      <NetworkConnect onmatch="include">
           <DestinationPort>443DestinationPort> 
           <DestinationPort>80DestinationPort>
      NetworkConnect>
      <NetworkConnect onmatch="exclude">
           <Image condition="end with">iexplore.exeImage>
      NetworkConnect>
      EventFiltering>
      Sysmon>
       -- 配置条目直接位于Sysmon 标签下, 过滤器位于 EventFiltering 标签下 
      
    • 过滤器标签
       ProcessCreate            进程创建
       FileCreateTime           文件创建时间更改
       NetworkConnect           检测到网络连接
       ProcessTerminate         进程终止
       DriverLoad               驱动程序已加载
       ImageLoad                镜像加载
       CreateRemoteThread       已检测到创建远程线程
       RawAccessRead            检测到原始访问读取
       ProcessAccess            已访问的进程
       FileCreate               文件创建
       RegistryEvent            添加或删除注册表对象
       RegistryEvent            注册表值设置
       RegistryEvent            注册表对象已重命名
       FileCreateStreamHash     已创建文件流
       PipeEvent                管道创建
       PipeEvent                管道已连接
       WmiEvent                 检测到WmiEventFilter活动 -- WmiEventFilter activity detected
       WmiEvent                 检测到WmiEventConsumer活动 -- WmiEventConsumer activity detected
       WmiEvent                 检测到WmiEventConsumerToFilter活动 -- WmiEventConsumerToFilter activity 
       DnsQuery                 DNS查询
      
      
    • 标签使用说明:
      使用onmacth标记配置文件中 过滤器规则 include exclude
      include:
           仅包含include的规则配置 
      exclude: 
           除去该规则配置, 其他全包含 
      PS: 
           例如,此规则将丢弃进程创建中 IntegrityLevel 为中等的任何流程事件
            
                Medium
           
      

    • 过滤器标签的字段可以使用其他条件匹配该值
    --------------------------------------
    注: 不区分大小写
    --------------------------------------
    字段如下:
         is             默认值, 等于
         is not         不等于 
         contains       包含
         excludes       不包含
         begin with     以此字段开始
         end with       以此字段结束
         less than      小于
         more than      大于 
         image          匹配镜像路径(完整路径或仅镜像名称) 
         例如:lsass.exe将匹配c:\windows\system32\lsass.exe
         
    -----------------------------------------
    
    

    • 规则组:
      <EventFiltering>
           <RuleGroup name="group 1" groupRelation="and"> 
                <ProcessCreate onmatch="include"> 
                <Image condition="contains">timeout.exeImage> 
                <CommandLine condition="contains">100CommandLine>
                ProcessCreate>
           RuleGroup>
           <RuleGroup groupRelation="or">
                <ProcessTerminate onmatch="include">
                <Image condition="contains">timeout.exeImage> 
                <Image condition="contains">ping.exeImage>
                ProcessTerminate>
           RuleGroup>
           <ImageLoad onmatch="include"/>
      EventFiltering>
      
      要让sysmon报告哪个规则匹配导致记录事件,请向规则添加名称:
      <NetworkConnect onmatch="exclude">
           
           <Image name="network iexplore" condition="contains">iexplore.exeImage>
      NetworkConnect>
      

  • 两个sysmon 配置文件
    	
    	
    	<Sysmon schemaversion="4.21">
    		
    		<HashAlgorithms>md5,sha256HashAlgorithms> 
    		<CheckRevocation/> 
    	
    		 
    		 
    		 
    	
    		<EventFiltering>
    	
    		
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<ProcessCreate onmatch="exclude">
    				
    				<ParentCommandLine condition="is">"C:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe" -EmbeddingParentCommandLine>
    				<CommandLine condition="is"> "whoami" CommandLine> 
    				<CommandLine condition="is"> "systeminfo" CommandLine> 
    				<CommandLine condition="begin with"> "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" CommandLine> 
    				<CommandLine condition="begin with">C:\Windows\system32\DllHost.exe /ProcessidCommandLine> 
    				<CommandLine condition="begin with">C:\Windows\system32\wbem\wmiprvse.exe -EmbeddingCommandLine> 
    				<CommandLine condition="begin with">C:\Windows\system32\wbem\wmiprvse.exe -secured -EmbeddingCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\wermgr.exe -uploadCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\SearchIndexer.exe /EmbeddingCommandLine> 
    				<CommandLine condition="is">C:\windows\system32\wermgr.exe -queuereportingCommandLine> 
    				<CommandLine condition="is">\??\C:\Windows\system32\autochk.exe *CommandLine> 
    				<CommandLine condition="is">\SystemRoot\System32\smss.exeCommandLine> 
    				<CommandLine condition="is">C:\Windows\System32\RuntimeBroker.exe -EmbeddingCommandLine> 
    				<Image condition="is">C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exeImage> 
    				<Image condition="is">C:\Windows\System32\TokenBrokerCookies.exeImage> 
    				<Image condition="is">C:\Windows\System32\plasrv.exeImage> 
    				<Image condition="is">C:\Windows\System32\wifitask.exeImage> 
    				<Image condition="is">C:\Windows\system32\CompatTelRunner.exeImage> 
    				<Image condition="is">C:\Windows\system32\PrintIsolationHost.exeImage> 
    				<Image condition="is">C:\Windows\system32\SppExtComObj.ExeImage> 
    				<Image condition="is">C:\Windows\system32\audiodg.exeImage> 
    				<Image condition="is">C:\Windows\system32\conhost.exeImage> 
    				<Image condition="is">C:\Windows\system32\mobsync.exeImage> 
    				<Image condition="is">C:\Windows\system32\musNotification.exeImage> 
    				<Image condition="is">C:\Windows\system32\musNotificationUx.exeImage> 
    				<Image condition="is">C:\Windows\system32\powercfg.exeImage> 
    				<Image condition="is">C:\Windows\system32\sndVol.exeImage> 
    				<Image condition="is">C:\Windows\system32\sppsvc.exeImage> 
    				<Image condition="is">C:\Windows\system32\wbem\WmiApSrv.exeImage> 
    				<IntegrityLevel condition="is">AppContainerIntegrityLevel> 
    				<ParentCommandLine condition="begin with">%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\WindowsParentCommandLine> 
    				<ParentCommandLine condition="is">C:\windows\system32\wermgr.exe -queuereportingParentCommandLine> 
    				<CommandLine condition="is">C:\WINDOWS\system32\devicecensus.exe UserCxtCommandLine>
    				<CommandLine condition="is">C:\Windows\System32\usocoreworker.exe -EmbeddingCommandLine>
    				<ParentImage condition="is">C:\Windows\system32\SearchIndexer.exeParentImage> 
    				
    				<Image condition="begin with">C:\Program Files\Windows DefenderImage> 
    				<Image condition="is">C:\Windows\system32\MpSigStub.exeImage> 
    				
    				
    				<CommandLine condition="is">C:\WINDOWS\System32\svchost.exe -k SafeMonorCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -s StateRepositoryCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -p -s camsvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodelCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k appmodel -p -s tiledatamodelsvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k camera -s FrameServerCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k dcomlaunch -s LSMCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlayCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k defragsvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k imgsvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s EventSystemCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s bthservCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k LocalService -p -s BthAvctpSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s nsiCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localService -s w32TimeCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonationCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s DhcpCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLogCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -s BTAGServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbServiceCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestrictedCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p -s SSDPSRVCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNoNetworkCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnumCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpServiceCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnumCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvcCommandLine>  
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvcCommandLine>  
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvrCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauservCommandLine>
    				<CommandLine condition="is">C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnvCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHostCommandLine> 
    				<CommandLine condition="is">C:\Windows\System32\svchost.exe -k localSystemNetworkRestricted -p -s WdiSystemHostCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestrictedCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s BDESVCCommandLine> 
    				<CommandLine condition="is">C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVCCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s BITSCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s BITSCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -p -s AppinfoCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s GpsvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s SENSCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnvCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s ThemesCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcs -s WinmgmtCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcsCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -p -s DoSvcCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s DnscacheCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstationCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s NlaSvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkService -s TermServiceCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkServiceCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k networkServiceNetworkRestrictedCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k rPCSSCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k secsvcsCommandLine>
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k swprvCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k unistackSvcGroupCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k utcsvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wbioSvcGroupCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k werSvcGroupCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\System32\svchost.exe -k wsappx -p -s ClipSVCCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvcCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappx -s ClipSVCCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\svchost.exe -k wsappxCommandLine> 
    				<ParentCommandLine condition="is">C:\Windows\system32\svchost.exe -k netsvcsParentCommandLine> 
    				<ParentCommandLine condition="is">C:\Windows\system32\svchost.exe -k localSystemNetworkRestrictedParentCommandLine> 
    				<CommandLine condition="is">C:\Windows\system32\deviceenroller.exe /c /AutoEnrollMDMCommandLine> 
    				
    				<CommandLine condition="begin with">"C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe" --type=CommandLine>
    				
    				<CommandLine condition="begin with">C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeCommandLine> 
    				<CommandLine condition="begin with">C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\Ngen.exeCommandLine> 
    				<Image condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exeImage> 
    				<Image condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exeImage> 
    				<Image condition="is">C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exeImage> 
    				<ParentCommandLine condition="contains">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exeParentCommandLine>
    				<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exeParentImage> 
    				<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exeParentImage> 
    				<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exeParentImage> 
    				<ParentImage condition="is">C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exeParentImage> 
    				
    				<Image condition="is">C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXEImage> 
    				<Image condition="is">C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEImage> 
    				<Image condition="is">C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXEImage> 
    				<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXEImage> 
    				<Image condition="is">C:\Program Files\Microsoft Office\Office16\msoia.exeImage> 
    				<Image condition="is">C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exeImage>
    				
    				<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeImage> 
    				<ParentImage condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exeParentImage> 
    				<ParentImage condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeParentImage> 
    				
    				<Image condition="is">C:\Program Files\Windows Media Player\wmpnscfg.exeImage> 
    				
    				<CommandLine condition="begin with">"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=CommandLine> 
    				<CommandLine condition="begin with">"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=CommandLine> 
    				
    				<CommandLine condition="begin with">"C:\Program Files\Mozilla Firefox\plugin-container.exe" --channelCommandLine> 
    				<CommandLine condition="begin with">"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channelCommandLine> 
    				
    				<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exeParentImage>
    				
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exeImage> 
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\LogTransport2.exeImage> 
    				
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\AcroCEF\AcroCEF.exeImage> 
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\LogTransport2.exeImage> 
    				
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeImage> 
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\LogTransport2.exeImage> 
    				<CommandLine condition="begin with">"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" /CR CommandLine> 
    				<CommandLine condition="begin with">"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=CommandLine> 
    				
    				<Image condition="is">C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeImage> 
    				
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exeImage> 
    				<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exeParentImage> 
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeImage> 
    				
    				<Image condition="is">C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exeImage>
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exeImage>
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exeImage> 
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exeImage> 
    				<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exeParentImage> 
    				<Image condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exeImage>
    				<ParentImage condition="is">C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exeParentImage>
    				
    				<Image condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exeImage>
    				<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exeParentImage>
    				<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exeParentImage>
    				<ParentImage condition="is">C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exeParentImage>
    				
    				<ParentImage condition="is">C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\agent.exeParentImage> 
    				
    					
    				<CommandLine condition="is">C:\Windows\system32\igfxsrvc.exe -EmbeddingCommandLine>
    				<ParentImage condition="is">C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exeParentImage> 
    			ProcessCreate>
    		RuleGroup>
    		
    		
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<FileCreateTime onmatch="include">
    				<Image name="T1099" condition="begin with">C:\UsersImage> 
    				<TargetFilename name="T1099" condition="end with">.exeTargetFilename> 
    				<Image name="T1099" condition="begin with">\Device\HarddiskVolumeShadowCopyImage> 
    			FileCreateTime>
    	
    			<FileCreateTime onmatch="exclude">
    				<Image condition="image">OneDrive.exeImage> 
    				<Image condition="image">C:\Windows\system32\backgroundTaskHost.exeImage>
    				<Image condition="contains">setupImage> 
    				<Image condition="contains">installImage> 
    				<Image condition="contains">Update\Image> 
    				<Image condition="end with">redist.exeImage> 
    				<Image condition="is">msiexec.exeImage> 
    				<Image condition="is">TrustedInstaller.exeImage> 
    			FileCreateTime>
    		RuleGroup>
    	
    		
    			
    			
    			
    			
    			
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<NetworkConnect onmatch="include">
    				
    				<Image name="Usermode" condition="begin with">C:\UsersImage> 
    				<Image name="Caution!" condition="begin with">C:\RecyleImage> 
    				<Image condition="begin with">C:\ProgramDataImage> 
    				<Image condition="begin with">C:\Windows\TempImage> 
    				<Image name="Caution!" condition="begin with">\Image> 
    				<Image name="Caution!" condition="begin with">C:\perflogsImage> 
    				<Image name="Caution!" condition="begin with">C:\intelImage> 
    				<Image name="Caution!" condition="begin with">C:\Windows\fontsImage> 
    				<Image name="Caution!" condition="begin with">C:\Windows\system32\configImage> 
    				
    				<Image condition="image">at.exeImage> 
    				<Image condition="image">certutil.exeImage> 
    				<Image condition="image">cmd.exeImage> 
    				<Image condition="image">cmstp.exeImage> 
    				<Image condition="image">cscript.exeImage> 
    				<Image condition="image">driverquery.exeImage> 
    				<Image condition="image">dsquery.exeImage> 
    				<Image condition="image">hh.exeImage> 
    				<Image condition="image">infDefaultInstall.exeImage> 
    				<Image condition="image">java.exeImage> 
    				<Image condition="image">javaw.exeImage> 
    				<Image condition="image">javaws.exeImage> 
    				<Image condition="image">mmc.exeImage> 
    				<Image condition="image">msbuild.exeImage> 
    				<Image condition="image">mshta.exeImage> 
    				<Image condition="image">msiexec.exeImage> 
    				<Image condition="image">nbtstat.exeImage> 
    				<Image condition="image">net.exeImage> 
    				<Image condition="image">net1.exeImage> 
    				<Image condition="image">notepad.exeImage> 
    				<Image condition="image">nslookup.exeImage> 
    				<Image condition="image">powershell.exeImage> 
    				<Image condition="image">qprocess.exeImage> 
    				<Image condition="image">qwinsta.exeImage> 
    				<Image condition="image">qwinsta.exeImage> 
    				<Image condition="image">reg.exeImage> 
    				<Image condition="image">regsvcs.exeImage> 
    				<Image condition="image">regsvr32.exeImage> 
    				<Image condition="image">rundll32.exeImage> 
    				<Image condition="image">rwinsta.exeImage> 
    				<Image condition="image">sc.exeImage> 
    				<Image condition="image">schtasks.exeImage> 
    				<Image condition="image">taskkill.exeImage> 
    				<Image condition="image">tasklist.exeImage> 
    				<Image condition="image">wmic.exeImage> 
    				<Image condition="image">wscript.exeImage> 
    				
    				<Image condition="image">nc.exeImage> 
    				<Image condition="image">ncat.exeImage> 
    				<Image condition="image">psexec.exeImage> 
    				<Image condition="image">psexesvc.exeImage> 
    				<Image condition="image">tor.exeImage> 
    				<Image condition="image">vnc.exeImage> 
    				<Image condition="image">vncservice.exeImage> 
    				<Image condition="image">vncviewer.exeImage> 
    				<Image condition="image">winexesvc.exeImage> 
    				<Image condition="image">nmap.exeImage>
    				<Image condition="image">psinfo.exeImage>
    				<Image condition="image">bitsadmin.exeImage>
    				
    				<DestinationPort name="CVE-2017-11882" condition="is">587DestinationPort>
    				<DestinationPort name="SMB" condition="is">139DestinationPort>
    				<DestinationPort name="SMB" condition="is">445DestinationPort>
    				<DestinationPort name="RPC" condition="is">135DestinationPort>
    				<DestinationPort name="DNS" condition="is">53DestinationPort>
    				<DestinationPort name="HTTPS" condition="is">443DestinationPort>
    				<DestinationPort name="FTP" condition="is">21DestinationPort> 
    				<DestinationPort name="SSH" condition="is">22DestinationPort> 
    				<DestinationPort name="Telnet" condition="is">23DestinationPort> 
    				<DestinationPort name="SMTP" condition="is">25DestinationPort> 
    				<DestinationPort name="IMAP" condition="is">142DestinationPort> 
    				<DestinationPort name="RDP" condition="is">3389DestinationPort> 
    				<DestinationPort name="VNC" condition="is">5800DestinationPort> 
    				<DestinationPort name="VNC" condition="is">5900DestinationPort> 
    				<DestinationPort name="Alert,Metasploit" condition="begin with">4444DestinationPort>
    				<DestinationPort name="Alert,Metasploit" condition="begin with">4445DestinationPort>
    				<DestinationPort name="Alert,Metasploit" condition="begin with">4446DestinationPort>
    				<DestinationPort name="Alert,Metasploit" condition="end with">1337DestinationPort>
    				
    				<DestinationPort name="Proxy" condition="is">1080DestinationPort> 
    				<DestinationPort name="Proxy" condition="is">3128DestinationPort> 
    				<DestinationPort name="Proxy" condition="is">8080DestinationPort> 
    				
    				<DestinationPort name="Tor" condition="is">1723DestinationPort> 
    				<DestinationPort name="Tor/IPsec" condition="is">4500DestinationPort> 
    				<DestinationPort name="Tor" condition="is">9001DestinationPort> 
    				<DestinationPort name="Tor" condition="is">9030DestinationPort> 
    			NetworkConnect>
    	
    			<NetworkConnect onmatch="exclude">
    				
    				<Image condition="end with">AppData\Roaming\Dropbox\bin\Dropbox.exeImage> 
    				<Image condition="end with">AppData\Local\Microsoft\Teams\current\Teams.exeImage> 
    				<Image condition="end with">AppData\Roaming\Spotify\Spotify.exeImage> 
    				
    				<Image condition="end with">AppData\Local\Microsoft\Teams\current\Teams.exeImage> 
    				<DestinationHostname condition="end with">.microsoft.comDestinationHostname> 
    				<DestinationHostname condition="end with">microsoft.com.akadns.netDestinationHostname> 
    				<DestinationHostname condition="end with">microsoft.com.nsatc.netDestinationHostname> 
    			NetworkConnect>
    		RuleGroup>
    	
    		
    	
    			
    			
    	
    		
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<ProcessTerminate onmatch="include">
    				<Image condition="begin with">C:\UsersImage> 
    				<Image condition="begin with">\Image> 
    			ProcessTerminate>
    	
    			<ProcessTerminate onmatch="exclude">
    			ProcessTerminate>
    		RuleGroup>
    	
    		
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<DriverLoad onmatch="exclude">
    				<Signature condition="contains">microsoftSignature> 
    				<Signature condition="contains">windowsSignature> 
    				<Signature condition="begin with">Intel Signature> 
    			DriverLoad>
    		RuleGroup>
    	
    		
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<ImageLoad onmatch="include">
    				
    			ImageLoad>
    		RuleGroup>
    	
    		
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<CreateRemoteThread onmatch="exclude">
    				
    				<SourceImage condition="is">C:\Windows\system32\wbem\WmiPrvSE.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\svchost.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\wininit.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\csrss.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\services.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\winlogon.exeSourceImage>
    				<SourceImage condition="is">C:\Windows\system32\audiodg.exeSourceImage>
    				<StartModule condition="is">C:\Windows\system32\kernel32.dllStartModule>
    				<TargetImage condition="is">C:\Program Files (x86)\Google\Chrome\Application\chrome.exeTargetImage> 
    			CreateRemoteThread>
    		RuleGroup>
    	
    		
    			
    			
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<RawAccessRead onmatch="include">
    				
    			RawAccessRead>
    		RuleGroup>
    	
    		
    			
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<ProcessAccess onmatch="include">
    				
    			ProcessAccess>
    		RuleGroup>
    	
    		
    			
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<FileCreate onmatch="include">
    				<TargetFilename name="T1023" condition="contains">\Start MenuTargetFilename> 
    				<TargetFilename name="T1165" condition="contains">\Startup\TargetFilename> 
    				<TargetFilename condition="contains">\Content.Outlook\TargetFilename> 
    				<TargetFilename name="FileCreate-Downloads" condition="contains">\Downloads\TargetFilename> 
    				<TargetFilename condition="end with">.applicationTargetFilename> 
    				<TargetFilename condition="end with">.appref-msTargetFilename> 
    				<TargetFilename condition="end with">.batTargetFilename> 
    				<TargetFilename condition="end with">.chmTargetFilename>
    				<TargetFilename condition="end with">.cmdTargetFilename> 
    				<TargetFilename condition="end with">.cmdlineTargetFilename> 
    				<TargetFilename name="T1176" condition="end with">.crxTargetFilename> 
    				<TargetFilename condition="end with">.docmTargetFilename> 
    				<TargetFilename condition="end with">.dllTargetFilename> 
    				<TargetFilename condition="end with">.exeTargetFilename> 
    				<TargetFilename condition="end with">.jarTargetFilename> 
    				<TargetFilename condition="end with">.jnlpTargetFilename> 
    				<TargetFilename condition="end with">.jseTargetFilename> 
    				<TargetFilename condition="end with">.htaTargetFilename> 
    				<TargetFilename condition="end with">.pptmTargetFilename> 
    				<TargetFilename condition="end with">.ps1TargetFilename> 
    				<TargetFilename condition="end with">.sysTargetFilename> 
    				<TargetFilename condition="end with">.scrTargetFilename> 
    				<TargetFilename condition="end with">.vbeTargetFilename> 
    				<TargetFilename condition="end with">.vbsTargetFilename> 
    				<TargetFilename condition="end with">.xlsmTargetFilename> 
    				<TargetFilename condition="end with">projTargetFilename>
    				<TargetFilename condition="end with">.slnTargetFilename>
    				<TargetFilename condition="begin with">C:\Users\DefaultTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\system32\DriversTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\SysWOW64\DriversTargetFilename> 
    				<TargetFilename name="T1037,T1484" condition="begin with">C:\Windows\system32\GroupPolicy\Machine\ScriptsTargetFilename> 
    				<TargetFilename name="T1037,T1484" condition="begin with">C:\Windows\system32\GroupPolicy\User\ScriptsTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\system32\WbemTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\SysWOW64\WbemTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\system32\WindowsPowerShellTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\SysWOW64\WindowsPowerShellTargetFilename> 
    				<TargetFilename name="T1053" condition="begin with">C:\Windows\Tasks\TargetFilename> 
    				<TargetFilename name="T1053" condition="begin with">C:\Windows\system32\TasksTargetFilename> 
    				<Image condition="begin with">\Device\HarddiskVolumeShadowCopyImage> 
    				
    				<TargetFilename condition="begin with">C:\Windows\AppPatch\CustomTargetFilename> 
    				<TargetFilename condition="contains">VirtualStoreTargetFilename> 
    				
    				<TargetFilename condition="end with">.xlsTargetFilename> 
    				<TargetFilename condition="end with">.pptTargetFilename> 
    				<TargetFilename condition="end with">.rtfTargetFilename> 
    			FileCreate>
    	
    			<FileCreate onmatch="exclude">
    				
    				<Image condition="is">C:\Program Files (x86)\EMET 5.5\EMET_Service.exeImage> 
    				
    				<TargetFilename condition="is">C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTaskTargetFilename>
    				
    				<Image condition="is">C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exeImage> 
    				
    				<Image condition="is">C:\Windows\system32\smss.exeImage> 
    				<Image condition="is">C:\Windows\system32\CompatTelRunner.exeImage> 
    				<Image condition="is">\\?\C:\Windows\system32\wbem\WMIADAP.EXEImage> 
    				<Image condition="is">C:\Windows\system32\mobsync.exeImage> 
    				<TargetFilename condition="begin with">C:\Windows\system32\DriverStore\Temp\TargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\system32\wbem\Performance\TargetFilename> 
    				<TargetFilename condition="end with">WRITABLE.TSTTargetFilename> 
    				<TargetFilename condition="begin with">C:\Windows\Installer\TargetFilename> 
    				
    				<TargetFilename condition="begin with">C:\$WINDOWS.~BT\Sources\TargetFilename> 
    				<Image condition="begin with">C:\Windows\winsxs\amd64_microsoft-windowsImage> 
    				
    				<Image condition="is">C:\Windows\system32\igfxCUIService.exeImage> 
    			FileCreate>
    		RuleGroup>
    	
    		
    			
    			
    			
    	
    			
    			
    			
    			
    	
    			
    			
    			
    			
    			
    	
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<RegistryEvent onmatch="include">
    				
    					
    					
    					
    					
    				<TargetObject name="T1060,RunKey" condition="contains">CurrentVersion\RunTargetObject> 
    				<TargetObject name="T1060,RunPolicy" condition="contains">Policies\Explorer\RunTargetObject> 
    				<TargetObject name="T1484" condition="contains">Group Policy\ScriptsTargetObject> 
    				<TargetObject name="T1484" condition="contains">Windows\System\ScriptsTargetObject> 
    				<TargetObject name="T1060" condition="contains">CurrentVersion\Windows\LoadTargetObject> 
    				<TargetObject name="T1060" condition="contains">CurrentVersion\Windows\RunTargetObject> 
    				<TargetObject name="T1060" condition="contains">CurrentVersion\Winlogon\ShellTargetObject> 
    				<TargetObject name="T1060" condition="contains">CurrentVersion\Winlogon\SystemTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\NotifyTargetObject> 
    				<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ShellTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserinitTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32TargetObject> 
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecuteTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebugTargetObject> 
    				<TargetObject condition="contains">UserInitMprLogonScriptTargetObject> 
    				<TargetObject name="T1112,ChangeStartupFolderPath" condition="end with">user shell folders\startupTargetObject> 
    				
    				<TargetObject name="T1031,T1050" condition="end with">\ServiceDllTargetObject> 
    				<TargetObject name="T1031,T1050" condition="end with">\ServiceManifestTargetObject> 
    				<TargetObject name="T1031,T1050" condition="end with">\ImagePathTargetObject> 
    				<TargetObject name="T1031,T1050" condition="end with">\StartTargetObject> 
    				
    				<TargetObject name="RDP port change" condition="end with">Control\Terminal Server\WinStations\RDP-Tcp\PortNumberTargetObject> 
    				<TargetObject name="RDP port change" condition="end with">Control\Terminal Server\fSingleSessionPerUserTargetObject>
    				<TargetObject name="ModifyRemoteDesktopState" condition="end with">fDenyTSConnectionsTargetObject>
    				<TargetObject condition="end with">LastLoggedOnUserTargetObject>
    				<TargetObject name="ModifyRemoteDesktopPort" condition="end with">RDP-tcp\PortNumberTargetObject>
    				<TargetObject condition="end with">Services\PortProxy\v4tov4TargetObject>
    	
    				
    				<TargetObject name="T1042" condition="contains">\command\TargetObject> 
    				<TargetObject name="T1122" condition="contains">\ddeexec\TargetObject> 
    				<TargetObject name="T1122" condition="contains">{86C86720-42A0-1069-A2E8-08002B30309D}TargetObject> 
    				<TargetObject name="T1042" condition="contains">exefileTargetObject> 
    				
    				<TargetObject condition="end with">\InprocServer32\(Default)TargetObject> 
    				
    				<TargetObject name="T1158" condition="end with">\HiddenTargetObject> 
    				<TargetObject name="T1158" condition="end with">\ShowSuperHiddenTargetObject> 
    				<TargetObject name="T1158" condition="end with">\HideFileExtTargetObject> 
    				
    				<TargetObject condition="contains">Classes\*\TargetObject> 
    				<TargetObject condition="contains">Classes\AllFilesystemObjects\TargetObject> 
    				<TargetObject condition="contains">Classes\Directory\TargetObject> 
    				<TargetObject condition="contains">Classes\Drive\TargetObject> 
    				<TargetObject condition="contains">Classes\Folder\TargetObject> 
    				<TargetObject condition="contains">ContextMenuHandlers\TargetObject> 
    				<TargetObject condition="contains">CurrentVersion\ShellTargetObject> 
    				<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooksTargetObject> 
    				<TargetObject condition="begin with">HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoadTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiersTargetObject> 
    				
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TargetObject> 
    				
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgramTargetObject> 
    				
    				<TargetObject name="T1484" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\TargetObject> 
    				
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\WinSock\TargetObject> 
    				<TargetObject condition="end with">\ProxyServerTargetObject> 
    				
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential ProviderTargetObject> 
    				<TargetObject name="T1101" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\TargetObject> 
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProvidersTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\NetshTargetObject> 
    				
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\TargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\ProfilesTargetObject> 
    				<TargetObject name="T1089" condition="end with">\EnableFirewallTargetObject> 
    				<TargetObject name="T1089" condition="end with">\DoNotAllowExceptionsTargetObject> 
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ListTargetObject> 
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ListTargetObject> 
    				
    				<TargetObject name="T1103" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\TargetObject> 
    				<TargetObject name="T1103" condition="begin with">HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\TargetObject> 
    				<TargetObject condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\TargetObject> 
    				
    				<TargetObject name="T1137" condition="contains">Microsoft\Office\Outlook\Addins\TargetObject> 
    				<TargetObject name="T1137" condition="contains">Office Test\TargetObject> 
    				<TargetObject name="Context,ProtectedModeExitOrMacrosUsed" condition="contains">Security\Trusted Documents\TrustRecordsTargetObject> 
    				
    				<TargetObject name="T1176" condition="contains">Internet Explorer\Toolbar\TargetObject> 
    				<TargetObject name="T1176" condition="contains">Internet Explorer\Extensions\TargetObject> 
    				<TargetObject name="T1176" condition="contains">Browser Helper Objects\TargetObject> 
    				<TargetObject condition="end with">\DisableSecuritySettingsCheckTargetObject>
    				<TargetObject condition="end with">\3\1206TargetObject> 
    				<TargetObject condition="end with">\3\2500TargetObject> 
    				<TargetObject condition="end with">\3\1809TargetObject> 
    				
    				<TargetObject condition="contains">{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\TargetObject> 
    				<TargetObject name="Alert,Sysinternals Tool Used" condition="end with">\EulaAcceptedTargetObject> 
    				
    				<TargetObject condition="end with">\UrlUpdateInfoTargetObject> 
    				<TargetObject condition="end with">\InstallSourceTargetObject> 
    				
    				<TargetObject name="T1089,Tamper-Defender" condition="end with">\DisableAntiSpywareTargetObject> 
    				<TargetObject name="T1089,Tamper-Defender" condition="end with">\DisableAntiVirusTargetObject> 
    				
    				<TargetObject name="T1088" condition="end with">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUATargetObject> 
    				<TargetObject name="T1088" condition="end with">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicyTargetObject> 
    				
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AllAlertsDisabledTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverrideTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotifyTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\DisableMonitoringTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotifyTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverrideTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotifyTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotifyTargetObject> 
    				<TargetObject name="T1089,Tamper-SecCenter" condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealthTargetObject> 
    				
    				<TargetObject name="T1138,AppCompatShim" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CustomTargetObject> 
    				<TargetObject name="T1138,AppCompatShim" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDBTargetObject> 
    				<TargetObject condition="contains">VirtualStoreTargetObject> 
    				
    				<TargetObject name="T1183,IFEO" condition="begin with">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\TargetObject> 
    				<TargetObject name="Tamper-Safemode" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\TargetObject> 
    				<TargetObject name="Tamper-Winlogon" condition="begin with">HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\TargetObject> 
    				<TargetObject name="Context,DeviceConntectedOrUpdated" condition="end with">\FriendlyNameTargetObject> 
    				<TargetObject name="Context,MsiInstallerStarted" condition="is">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default)TargetObject> 
    				<TargetObject name="Tamper-Tracing" condition="begin with">HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32TargetObject> 
    				
    				<TargetObject name="InvDB-Path" condition="end with">\LowerCaseLongPathTargetObject> 
    				<TargetObject name="InvDB-Pub" condition="end with">\PublisherTargetObject> 
    				<TargetObject name="InvDB-Ver" condition="end with">\ProductVersionTargetObject> 
    				<TargetObject name="InvDB-CompileTimeClaim" condition="end with">\LinkDateTargetObject> 
    				<TargetObject name="InvDB" condition="contains">Compatibility Assistant\Store\TargetObject>
    				
    				<Image name="Suspicious,ImageBeginWithBackslash" condition="begin with">\Image> 
    			RegistryEvent>
    	
    			<RegistryEvent onmatch="exclude">
    			
    	
    			
    	
    				<TargetObject condition="begin with">HKLM\COMPONENTSTargetObject>
    	
    				
    	
    				
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\CacheTargetObject>
    				
    				<TargetObject condition="end with">Toolbar\WebBrowserTargetObject> 
    				<TargetObject condition="end with">Browser\ITBar7HeightTargetObject> 
    				<TargetObject condition="end with">Browser\ITBar7LayoutTargetObject> 
    				<TargetObject condition="end with">Internet Explorer\Toolbar\LockedTargetObject> 
    				<TargetObject condition="end with">Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93}TargetObject> 
    				<TargetObject condition="end with">}\PreviousPolicyAreasTargetObject> 
    				<TargetObject condition="contains">\Control\WMI\Autologger\TargetObject> 
    				<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\StartTargetObject> 
    				<TargetObject condition="end with">\Lsa\OfflineJoin\CurrentValueTargetObject> 
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\TargetObject> 
    				<TargetObject condition="contains">_Classes\AppXTargetObject>  
    				<TargetObject condition="begin with">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\TargetObject> 
    				
    				<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPidTargetObject> 
    				<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCacheTargetObject>  
    				<TargetObject condition="end with">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\DomainsTargetObject>  
    				
    				<TargetObject condition="end with">\Services\BITS\StartTargetObject> 
    				<TargetObject condition="end with">\services\clr_optimization_v2.0.50727_32\StartTargetObject> 
    				<TargetObject condition="end with">\services\clr_optimization_v2.0.50727_64\StartTargetObject> 
    				<TargetObject condition="end with">\services\clr_optimization_v4.0.30319_32\StartTargetObject> 
    				<TargetObject condition="end with">\services\clr_optimization_v4.0.30319_64\StartTargetObject> 
    				<TargetObject condition="end with">\services\deviceAssociationService\StartTargetObject> 
    				<TargetObject condition="end with">\services\fhsvc\StartTargetObject> 
    				<TargetObject condition="end with">\services\nal\StartTargetObject> 
    				<TargetObject condition="end with">\services\trustedInstaller\StartTargetObject> 
    				<TargetObject condition="end with">\services\tunnel\StartTargetObject> 
    				<TargetObject condition="end with">\services\usoSvc\StartTargetObject> 
    				
    				<TargetObject condition="end with">\UserChoice\ProgIdTargetObject>  
    				<TargetObject condition="end with">\UserChoice\HashTargetObject>  
    				<TargetObject condition="end with">\OpenWithList\MRUListTargetObject> 
    				<TargetObject condition="contains">Shell Extentions\CachedTargetObject>  
    				
    				<TargetObject condition="end with">HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroupsTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrderTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-IDTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-IDTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershellTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTimeTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrderTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-IDTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-IDTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershellTargetObject> 
    				<TargetObject condition="end with">SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTimeTargetObject> 
    				<TargetObject condition="contains">\safer\codeidentifiers\0\HASHES\{TargetObject> 
    				
    				<TargetObject condition="contains">VirtualStore\MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\TargetObject> 
    				
    				<Image condition="is">C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exeImage> 
    				<TargetObject condition="begin with">HKCR\VLC.TargetObject> 
    				<TargetObject condition="begin with">HKCR\iTunes.TargetObject> 
    				
    				<TargetObject condition="is">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{945a8954-c147-4acd-923f-40c45405a658}TargetObject> 
    			RegistryEvent>
    		RuleGroup>
    	
    		
    			
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<FileCreateStreamHash onmatch="include">
    				<TargetFilename name="FileStream-Downloads" condition="contains">DownloadsTargetFilename> 
    				<TargetFilename condition="contains">Temp\7zTargetFilename> 
    				<TargetFilename condition="contains">StartupTargetFilename> 
    				<TargetFilename condition="end with">.batTargetFilename> 
    				<TargetFilename condition="end with">.cmdTargetFilename> 
    				<TargetFilename condition="end with">.htaTargetFilename> 
    				<TargetFilename condition="end with">.lnkTargetFilename> 
    				<TargetFilename condition="end with">.ps1TargetFilename> 
    				<TargetFilename condition="end with">.ps2TargetFilename> 
    				<TargetFilename condition="end with">.regTargetFilename> 
    				<TargetFilename condition="end with">.jseTargetFilename> 
    				<TargetFilename condition="end with">.vbTargetFilename> 
    				<TargetFilename condition="end with">.vbeTargetFilename> 
    				<TargetFilename condition="end with">.vbsTargetFilename> 
    			FileCreateStreamHash>
    	
    			<FileCreateStreamHash onmatch="exclude">
    			FileCreateStreamHash>
    		RuleGroup>
    	
    		
    			
    			
    			
    			
    			
    	
    		
    			
    			
    	
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<PipeEvent onmatch="include">
    				
    			PipeEvent>
    		RuleGroup>
    	
    		
    			
    			
    			
    	
    			
    			
    	
    			
    		<RuleGroup name="" groupRelation="or">
    			<WmiEvent onmatch="exclude">
    				
    			WmiEvent>
    		RuleGroup>
    	
    		
    			
    	
    			
    	
    			
    	
    			
    	
    			
    	
    			
    			
    			
    			
    	
    			
    			
    	
    			
    	
    			
    			
    			
    			
    			
    			
    	
    		<RuleGroup name="" groupRelation="or">
    			<DnsQuery onmatch="exclude">
    				
    				<QueryName condition="end with">.arpa.QueryName> 
    				<QueryName condition="end with">.arpaQueryName> 
    				<QueryName condition="end with">.msftncsi.comQueryName> 
    				<QueryName condition="is">..localmachineQueryName>
    				
    				<QueryName condition="end with">-pushp.svc.msQueryName> 
    				<QueryName condition="end with">.b-msedge.netQueryName> 
    				<QueryName condition="end with">.bing.comQueryName> 
    				<QueryName condition="end with">.hotmail.comQueryName> 
    				<QueryName condition="end with">.live.comQueryName> 
    				<QueryName condition="end with">.live.netQueryName> 
    				<QueryName condition="end with">.s-microsoft.comQueryName> 
    				<QueryName condition="end with">.microsoft.comQueryName> 
    				<QueryName condition="end with">.microsoftonline.comQueryName> 
    				<QueryName condition="end with">.microsoftstore.comQueryName> 
    				<QueryName condition="end with">.ms-acdc.office.comQueryName> 
    				<QueryName condition="end with">.msedge.netQueryName> 
    				<QueryName condition="end with">.msn.comQueryName> 
    				<QueryName condition="end with">.msocdn.comQueryName> 
    				<QueryName condition="end with">.skype.comQueryName> 
    				<QueryName condition="end with">.skype.netQueryName> 
    				<QueryName condition="end with">.windows.comQueryName> 
    				<QueryName condition="end with">.windows.net.nsatc.netQueryName> 
    				<QueryName condition="end with">.windowsupdate.comQueryName> 
    				<QueryName condition="end with">.xboxlive.comQueryName> 
    				<QueryName condition="is">login.windows.netQueryName> 
    				
    				<QueryName condition="end with">.activedirectory.windowsazure.comQueryName> 
    				<QueryName condition="end with">.aria.microsoft.comQueryName> 
    				<QueryName condition="end with">.msauth.netQueryName>
    				<QueryName condition="end with">.msftauth.netQueryName>
    				<QueryName condition="end with">.opinsights.azure.comQueryName> 
    				<QueryName condition="is">management.azure.comQueryName> 
    				<QueryName condition="is">outlook.office365.comQueryName> 
    				<QueryName condition="is">portal.azure.comQueryName> 
    				
    				<QueryName condition="end with">.mozaws.netQueryName> 
    				<QueryName condition="end with">.mozilla.comQueryName> 
    				<QueryName condition="end with">.mozilla.netQueryName> 
    				<QueryName condition="end with">.mozilla.orgQueryName> 
    				<QueryName condition="end with">.spotify.comQueryName> 
    				<QueryName condition="end with">.spotify.map.fastly.netQueryName> 
    				<QueryName condition="is">clients1.google.comQueryName> 
    				<QueryName condition="is">clients2.google.comQueryName> 
    				<QueryName condition="is">clients3.google.comQueryName> 
    				<QueryName condition="is">clients4.google.comQueryName> 
    				<QueryName condition="is">clients5.google.comQueryName> 
    				<QueryName condition="is">clients6.google.comQueryName> 
    				<QueryName condition="is">safebrowsing.googleapis.comQueryName> 
    				
    				<QueryName condition="end with">.akadns.netQueryName> 
    				<QueryName condition="end with">.netflix.comQueryName>
    				<QueryName condition="end with">aspnetcdn.comQueryName> 
    				<QueryName condition="is">ajax.googleapis.comQueryName>
    				<QueryName condition="is">cdnjs.cloudflare.comQueryName> 
    				<QueryName condition="is">fonts.googleapis.comQueryName> 
    				<QueryName condition="end with">.typekit.netQueryName> 
    				<QueryName condition="is">cdnjs.cloudflare.comQueryName>
    	
    				
    				<QueryName condition="end with">.steamcontent.comQueryName> 
    				
    				<QueryName condition="end with">.disqus.comQueryName> 
    				<QueryName condition="end with">.fontawesome.comQueryName>
    				<QueryName condition="is">disqus.comQueryName> 
    				
    				<QueryName condition="end with">.2mdn.netQueryName> 
    				<QueryName condition="end with">.adadvisor.netQueryName> 
    				<QueryName condition="end with">.adap.tvQueryName> 
    				<QueryName condition="end with">.addthis.comQueryName> 
    				<QueryName condition="end with">.adform.netQueryName> 
    				<QueryName condition="end with">.adnxs.comQueryName> 
    				<QueryName condition="end with">.adroll.comQueryName> 
    				<QueryName condition="end with">.adsafeprotected.comQueryName> 
    				<QueryName condition="end with">.adsrvr.orgQueryName> 
    				<QueryName condition="end with">.advertising.comQueryName> 
    				<QueryName condition="end with">.amazon-adsystem.comQueryName> 
    				<QueryName condition="end with">.amazon-adsystem.comQueryName> 
    				<QueryName condition="end with">.analytics.yahoo.comQueryName> 
    				<QueryName condition="end with">.aol.comQueryName> 
    				<QueryName condition="end with">.betrad.comQueryName> 
    				<QueryName condition="end with">.bidswitch.netQueryName> 
    				<QueryName condition="end with">.casalemedia.comQueryName> 
    				<QueryName condition="end with">.chartbeat.netQueryName> 
    				<QueryName condition="end with">.cnn.comQueryName> 
    				<QueryName condition="end with">.convertro.comQueryName> 
    				<QueryName condition="end with">.criteo.comQueryName> 
    				<QueryName condition="end with">.criteo.netQueryName> 
    				<QueryName condition="end with">.crwdcntrl.netQueryName> 
    				<QueryName condition="end with">.demdex.netQueryName> 
    				<QueryName condition="end with">.domdex.comQueryName> 
    				<QueryName condition="end with">.dotomi.comQueryName> 
    				<QueryName condition="end with">.doubleclick.netQueryName> 
    				<QueryName condition="end with">.doubleverify.comQueryName> 
    				<QueryName condition="end with">.emxdgt.comQueryName> 
    				<QueryName condition="end with">.exelator.comQueryName> 
    				<QueryName condition="end with">.google-analytics.comQueryName> 
    				<QueryName condition="end with">.googleadservices.comQueryName> 
    				<QueryName condition="end with">.googlesyndication.comQueryName> 
    				<QueryName condition="end with">.googletagmanager.comQueryName> 
    				<QueryName condition="end with">.googlevideo.comQueryName> 
    				<QueryName condition="end with">.gstatic.comQueryName> 
    				<QueryName condition="end with">.gvt1.comQueryName> 
    				<QueryName condition="end with">.gvt2.comQueryName> 
    				<QueryName condition="end with">.ib-ibi.comQueryName> 
    				<QueryName condition="end with">.jivox.comQueryName> 
    				<QueryName condition="end with">.mathtag.comQueryName> 
    				<QueryName condition="end with">.moatads.comQueryName> 
    				<QueryName condition="end with">.moatpixel.comQueryName> 
    				<QueryName condition="end with">.mookie1.comQueryName> 
    				<QueryName condition="end with">.myvisualiq.netQueryName> 
    				<QueryName condition="end with">.netmng.comQueryName> 
    				<QueryName condition="end with">.nexac.comQueryName> 
    				<QueryName condition="end with">.nexac.comQueryName> 
    				<QueryName condition="end with">.openx.netQueryName> 
    				<QueryName condition="end with">.optimizely.comQueryName> 
    				<QueryName condition="end with">.outbrain.comQueryName> 
    				<QueryName condition="end with">.pardot.comQueryName> 
    				<QueryName condition="end with">.phx.gblQueryName> 
    				<QueryName condition="end with">.pinterest.comQueryName> 
    				<QueryName condition="end with">.pubmatic.comQueryName> 
    				<QueryName condition="end with">.quantcount.comQueryName>
    				<QueryName condition="end with">.quantserve.comQueryName>
    				<QueryName condition="end with">.revsci.netQueryName> 
    				<QueryName condition="end with">.rfihub.netQueryName> 
    				<QueryName condition="end with">.rlcdn.comQueryName> 
    				<QueryName condition="end with">.rubiconproject.comQueryName> 
    				<QueryName condition="end with">.scdn.coQueryName> 
    				<QueryName condition="end with">.scorecardresearch.comQueryName> 
    				<QueryName condition="end with">.serving-sys.comQueryName> 
    				<QueryName condition="end with">.sharethrough.comQueryName> 
    				<QueryName condition="end with">.simpli.fiQueryName>
    				<QueryName condition="end with">.sitescout.comQueryName> 
    				<QueryName condition="end with">.smartadserver.comQueryName> 
    				<QueryName condition="end with">.snapads.comQueryName> 
    				<QueryName condition="end with">.spotxchange.comQueryName> 
    				<QueryName condition="end with">.1rx.ioQueryName> 
    				<QueryName condition="end with">.adrta.comQueryName> 
    				<QueryName condition="end with">.taboola.comQueryName> 
    				<QueryName condition="end with">.taboola.map.fastly.netQueryName> 
    				<QueryName condition="end with">.tapad.comQueryName>
    				<QueryName condition="end with">.tidaltv.comQueryName> 
    				<QueryName condition="end with">.trafficmanager.netQueryName> 
    				<QueryName condition="end with">.tremorhub.comQueryName> 
    				<QueryName condition="end with">.tribalfusion.comQueryName> 
    				<QueryName condition="end with">.turn.comQueryName> 
    				<QueryName condition="end with">.twimg.comQueryName> 
    				<QueryName condition="end with">.tynt.comQueryName> 
    				<QueryName condition="end with">.w55c.netQueryName> 
    				<QueryName condition="end with">.ytimg.comQueryName> 
    				<QueryName condition="end with">.zorosrv.comQueryName> 
    				<QueryName condition="is">adservice.google.comQueryName> 
    				<QueryName condition="is">ampcid.google.comQueryName> 
    				<QueryName condition="is">clientservices.googleapis.comQueryName> 
    				<QueryName condition="is">d29x207vrinatv.cloudfront.netQueryName> 
    				<QueryName condition="is">googleadapis.l.google.comQueryName> 
    				<QueryName condition="is">imasdk.googleapis.comQueryName> 
    				<QueryName condition="is">l.google.comQueryName> 
    				<QueryName condition="is">ml314.comQueryName> 
    				<QueryName condition="is">mtalk.google.comQueryName> 
    				<QueryName condition="is">update.googleapis.comQueryName> 
    				<QueryName condition="is">1rx.ioQueryName>
    				<QueryName condition="is">www.googletagservices.comQueryName>
    				
    				<QueryName condition="end with">.pscp.tvQueryName> 
    				
    				<QueryName condition="end with">.digicert.comQueryName>
    				<QueryName condition="end with">.globalsign.comQueryName>
    				<QueryName condition="end with">.globalsign.netQueryName>
    				<QueryName condition="is">msocsp.comQueryName> 
    				<QueryName condition="is">ocsp.msocsp.comQueryName> 
    				<QueryName condition="end with">pki.googQueryName>
    				<QueryName condition="is">ocsp.godaddy.comQueryName>
    				<QueryName condition="end with">amazontrust.comQueryName>
    				<QueryName condition="is">ocsp.sectigo.comQueryName>
    				<QueryName condition="is">pki-goog.l.google.comQueryName>
    				<QueryName condition="end with">.usertrust.comQueryName>
    				<QueryName condition="is">ocsp.comodoca.comQueryName>
    				<QueryName condition="is">ocsp.verisign.comQueryName>
    				<QueryName condition="is">ocsp.entrust.netQueryName>
    				<QueryName condition="end with">ocsp.identrust.comQueryName>
    				<QueryName condition="is">status.rapidssl.comQueryName>
    				<QueryName condition="is">status.thawte.comQueryName>
    				<QueryName condition="is">ocsp.int-x3.letsencrypt.orgQueryName>
    			DnsQuery>
    		RuleGroup>
    	
    		
    			
    			
    	
    		EventFiltering>
    		Sysmon>
    
  • 全部事件收集
    <Sysmon schemaversion="4.21">
    
    <HashAlgorithms>*HashAlgorithms>
    <CheckRevocation/>
    <EventFiltering >
    <RuleGroup name="" groupRelation="or"> 
        <ProcessCreate onmatch="exclude">ProcessCreate>
        <FileCreateTime onmatch="exclude">FileCreateTime>
        <NetworkConnect onmatch="exclude">NetworkConnect>
        <ProcessTerminate onmatch="exclude">ProcessTerminate>
        <DriverLoad onmatch="exclude">DriverLoad>
        <ImageLoad onmatch="exclude">ImageLoad>
        <CreateRemoteThread onmatch="exclude">CreateRemoteThread>
        <RawAccessRead onmatch="exclude">RawAccessRead>
        <ProcessAccess onmatch="exclude">ProcessAccess>
        <FileCreate onmatch="exclude">FileCreate>
        <RegistryEvent onmatch="exclude">RegistryEvent>
        <FileCreateStreamHash onmatch="exclude">FileCreateStreamHash>
        <PipeEvent onmatch="exclude">PipeEvent>
        <DnsQuery onmatch="exclude">DnsQuery>
    RuleGroup>
    EventFiltering>
    
```

你可能感兴趣的:(安全)