I am using the latest version of Sysmon along with olafhartong's sysmonconfig.xml configuration https://github.com/olafhartong/sysmon-modula. Wazuh rules 102101-MITER_TECHNIQUES_FROM_SYSMON_EVENT3.xml are also installed on the server.
In the Event Viewer, I see the logs I need when establishing connections to remote computers.
For example, there are two logs (both have _RuleName: technique_id=T1021,techniquename=Remote Services): when establishing a connection through the TOTALCMD.EXE and RDCMan.exe processes, respectively.
Wazuh only accepts logs from TOTALCMD.EXE for some reason. I can't figure out what's wrong. Are there any suggestions that it might be wrong with your rules?
Greetings!
I am using the latest version of Sysmon along with olafhartong's sysmonconfig.xml configuration https://github.com/olafhartong/sysmon-modula. Wazuh rules 102101-MITER_TECHNIQUES_FROM_SYSMON_EVENT3.xml are also installed on the server.
In the Event Viewer, I see the logs I need when establishing connections to remote computers.
For example, there are two logs (both have _RuleName: technique_id=T1021,techniquename=Remote Services): when establishing a connection through the TOTALCMD.EXE and RDCMan.exe processes, respectively.
Wazuh only accepts logs from TOTALCMD.EXE for some reason. I can't figure out what's wrong. Are there any suggestions that it might be wrong with your rules?