SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.73k stars 1.69k forks source link

Added most of the missing LOLBAS for downloading executables #106

Closed MaxNad closed 2 years ago

MaxNad commented 4 years ago

I added most of the missing LOLBAS for downloading executables in the Event id 3 section for network connections. I also removed a bit of noise coming from missing windows process exclusions.

Here are the in-depth changes : Process Launch (Event ID 1)

I did not add update.exe from Teams since it would generate too many false positives.

Do not hesitate to comment this issue if you feel like some of those items are unclear or should be removed / modified.

Thank you for the great work, Have a good day.

SwiftOnSecurity commented 2 years ago

Thanks